Account Takeover
The latest Account Takeover coverage — news, analysis, and updates from the WindowsNews.AI desk.
Attackers Are Tricking Microsoft Users Into Adding Rogue Passkeys—Here’s the Fix
A vishing campaign that preys on Microsoft 365 users—persuading them by phone to enroll attacker-controlled passkeys—has been active since early 2025, security firm Okta warned on Wednesday. The...
Russian-Linked Phishing Campaign Targets Encrypted Messaging Users, CISA Warns
Russian state-linked cyber operators are again leaning on a familiar but still highly effective tactic: phishing the person instead of breaking the platform. The latest warning from CISA and the FBI...
Mendix SAML Signature Bypass Allows Remote Account Hijacking; Siemens Urges Immediate Patches
Siemens on August 14, 2025, disclosed a critical vulnerability in its Mendix SAML module that could allow unauthenticated attackers to bypass cryptographic signature verification and hijack user...
How Cybercriminals Exploit Trusted Email Security to Breach Microsoft 365
Cybercriminal activity is propelling a seismic change in the security calculus for organizations using Microsoft 365, with attackers now audaciously subverting the very email security mechanisms that...
2025 Microsoft OAuth Phishing Attacks: Evolving Threats Beyond MFA
Phishing campaigns continue to evolve at a staggering pace, keeping security professionals on perpetual alert. In 2025, the latest surge in Microsoft OAuth-centric phishing attacks illustrates just...
Microsoft 365 Security: Navigating OAuth Abuse, MFA Bypass, and Evolving Cyber Threats
The escalating arms race between cyber adversaries and defenders is perhaps nowhere more visible than in the evolving threat landscape targeting Microsoft 365. Once considered a relatively safe...
How TeamFiltration Protects Microsoft Entra ID from AI-Powered Cloud Identity Attacks
The cybersecurity landscape is witnessing a dangerous evolution as AI-driven attacks increasingly target Microsoft Entra ID (formerly Azure Active Directory), putting organizations at unprecedented...
Arkose Labs and Microsoft Partner to Revolutionize AI-Driven Cybersecurity
In an era where cyber threats evolve at an unprecedented pace, a groundbreaking partnership between Arkose Labs and Microsoft is set to redefine the landscape of AI-driven cybersecurity. This...
Cybersecurity Alert: New Research Reveals 78% of Microsoft 365 Users Targeted in Sophisticated Account Takeover Attacks
Introduction Recent research from cybersecurity firm Proofpoint has revealed a startling vulnerability in Microsoft's ecosystem: approximately 78% of Microsoft 365 users have been targeted by account...
Emerging Axios Attacks Pose Significant Threat to Microsoft 365 Security
Recent cybersecurity research has unveiled a concerning trend: Microsoft 365 users are increasingly targeted by sophisticated account takeover (ATO) attacks leveraging the Axios HTTP client. This...
HTTP Client Tools Exploited in Microsoft 365 Account Takeovers: Emerging Cybersecurity Threat
Microsoft 365 account takeovers are surging as attackers exploit HTTP client tools to bypass multi-factor authentication (MFA) protections. Security researchers have identified a sophisticated attack...