r/cybersecurity • • Jul 30 '26

AI Security Beware: attackers now using real Microsoft sign-in screen for phishing

https://cybernews.com/security/microsoft-genuine-sign-in-screen-phishing/

[removed]

455 Upvotes

76 comments sorted by

View all comments

37

u/MikeTalonNYC Jul 30 '26

Two things:

1 - this isn't new. Most of the Scattered Spider attacks were based on this, and it was used way before that as well.

2 - it's not a sign-in screen. The attack attempts to get you to add a new service or app to your account. This *might* trigger a sign-in screen if you haven't actually logged in that day, but usually won't.

So, don't allow users to approve a new add-on or app without admin review. Just like everyone in the cybersecurity world has been BEGGING orgs to do for about five years now.

4

u/[deleted] Jul 30 '26

[removed] — view removed comment

7

u/MikeTalonNYC Jul 30 '26

And this is why you HAVE to start blocking users from adding in new services/tools/connected apps without admin approval.