Data Science Wire

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Reddit r/deeplearning3d4 min read

Researchers documented a phishing campaign that impersonated passkey registration prompts, captured live session tokens after users authenticated through legitimate MFA flows, and then used those tokens to access Microsoft 365 tenants with full account privileges (Bleeping Computer). Victims had no indication anything was wrong. The attacker's session looked identical to a normal user session — same permissions, same scope, same API calls. The uncomfortable part: passkeys were the thing being used as bait precisely because users have been trained to trust that flow. The attack didn't break aut

Read the full story at Reddit r/deeplearning

More in Machine Learning