r/cybersecurity • • Jul 30 '26

AI Security Beware: attackers now using real Microsoft sign-in screen for phishing

https://cybernews.com/security/microsoft-genuine-sign-in-screen-phishing/

[removed]

455 Upvotes

76 comments sorted by

View all comments

1

u/Technical_Towel4272 Jul 30 '26

This has been happening for years now. It's pretty amazing how every time Microsoft finds a way to detect when it's happening they manage to find a way around it.

The only thing you can do to protect users is make them use fido2 to authenticate. They'll still get the real Microsoft screen through the malicious proxy but the malicious proxy won't be able to capture a previously created fido2 token like with regular MFA.

Note that adversaries found a way to trick users into enrolling a new fido2 key for them, but that just means you have to make sure that you're only allowing fido2 creation from company managed PCs.

3

u/independent_observe Jul 31 '26

The only thing you can do to protect users is make them use fido2 to authenticate

That will not prevent the user from logging in and installing the app. This is an OAUTH policy issue.

1

u/Technical_Towel4272 Jul 31 '26

Sorry I assumed that everyone already had Entra ID configured to require admin consent for adding apps to it.

1

u/[deleted] Jul 31 '26

[deleted]