Agregátor RSS

BigBear phishing crew nets thousands of Microsoft 365 credentials

The Register - Anti-Virus - 8 Září, 2026 - 15:26
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving them an unusually detailed look at the campaign and its haul. According to the researchers, the panel contained 5,137 records associated with 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies. CloudSEK classified 474 records as complete MFA-bypassed authentications in which the attackers captured an authenticated Microsoft 365 session. That potentially hands the crooks much more than an inbox. A hijacked Microsoft 365 account can expose email, calendars, Teams conversations, and files stored in SharePoint and OneDrive. Depending on the account's permissions, CloudSEK says it could also provide a route into Entra ID, cloud infrastructure, and federated SaaS applications – useful territory for business email compromise, internal phishing, data theft, and lateral movement. And this isn't a postmortem. CloudSEK said the BigBear operation was still active at the time of its investigation, with its default phishing template, dubbed "offy," configured specifically to intercept Microsoft 365 authentication. BigBear doesn't need to defeat Microsoft's MFA directly. Instead, its Evilginx2 infrastructure operates as an adversary-in-the-middle proxy between the victim and Microsoft's real login service. Victims arriving at one of the phishing sites see Microsoft's login flow proxied through the attacker's server. Their usernames and passwords are passed to Microsoft, along with whatever MFA challenges follow. Once the victim successfully authenticates, Microsoft returns a session cookie – which passes through the attacker's infrastructure on its way back. By stealing that cookie, the attacker can replay the authenticated session and potentially access Microsoft 365 services without prompting the victim to authenticate again, at least until the token expires or is revoked. Security researcher Gagan Aggarwal said BigBear's customizations go further than stock Evilginx2. Researchers found JavaScript designed to disable FIDO2/WebAuthn authentication on the phishing page, pushing users toward methods such as SMS codes, push notifications, and TOTP, which remain susceptible to this kind of proxy attack. The operation also uses a residential proxy pool covering 69 countries. If a victim is in India, for example, BigBear can route the upstream Microsoft login through an Indian residential IP, making the authentication appear less geographically suspicious. Another check attempts to block visitors arriving from datacenter, VPN, and proxy addresses, making life harder for automated scanners and researchers. CloudSEK says the infrastructure was managed through a multi-user panel and leased to at least five affiliate operators, with stolen credentials delivered in real time via separate Telegram bots. The researchers observed 42 VPS nodes over the campaign's lifetime. Twenty-six had been deleted from the panel since late July, and just one was active when CloudSEK examined it. Aggarwal says the person running BigBear goes by "General Boss." CloudSEK hasn't linked the operation to any known state-backed group and believes money is the motive. The stolen Microsoft 365 access could be used for business email compromise and data theft, or simply sold on to other criminals. CloudSEK recommends phishing-resistant FIDO2/WebAuthn authentication, conditional access policies, compliant device requirements, and the revocation of compromised session and refresh tokens. ®
Kategorie: Viry a Červi

Microsoft přitlačí na aktivaci bezpečnostní funkce, kvůli níž Windows 11 zavedly přísné hardwarové nároky

Živě.cz - 8 Září, 2026 - 14:45
Microsoft v říjnu zapne Kontrola integrity paměti na více počítačích. • Nevíme přesně, kterých verzí nebo edic se to týká. • Bezpečnostní funkci bude možné ponechat vypnutou.
Kategorie: IT News

Microsoft přitlačí na aktivaci bezpečnostní funkce, kvůli níž Windows 11 zavedly přísné hardwarové nároky

Zive.cz - bezpečnost - 8 Září, 2026 - 14:45
**Microsoft v říjnu zapne Kontrola integrity paměti na více počítačích. **Nevíme přesně, kterých verzí nebo edic se to týká. **Bezpečnostní funkci bude možné ponechat vypnutou.
Kategorie: Hacking & Security

Webinar: The forgotten Google Workspace access that can lead to a breach

Bleeping Computer - 8 Září, 2026 - 14:40
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
Kategorie: Hacking & Security

Hackers build AI frameworks for widescale credential theft

Bleeping Computer - 8 Září, 2026 - 14:03
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
Kategorie: Hacking & Security

Extortion crews have their eyes on high-value AI data, Google warns

The Register - Anti-Virus - 8 Září, 2026 - 14:00
Data theft and extortion crews are stealing companies’ proprietary AI data and threatening to leak it if the victim organizations don’t pay a ransom, according to Google’s threat hunters. In one case that Google’s Mandiant incident response team investigated, the crooks broke into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company met their extortion demand. In another breach at a company that specializes in AI media generation, attackers stole sensitive AI data including source code, prompts, skills, model scripts, and secrets before demanding a payment and threatening to dump the AI assets publicly if the ransom wasn’t paid. Google detailed these two intrusions for the first time in its most recent AI Threat Tracker, published Tuesday and shared in advance with The Register. “But it's certainly not limited to that,” John Hultquist, chief analyst at Google Threat Intelligence Group, said in an interview with The Register. Mandiant responded to several of these data-theft-and-extortion operations during the second quarter of 2026, he said. The intrusions affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors in North America and Europe. “It’s become a really valuable target where organizations are spending a lot of money and investment, and they don't necessarily want their IP exposed to the open world, so they're willing to pay in an extortion scheme,” Hultquist said. “Criminals attacking AI systems is an area that's not received as much attention as it probably should, and as we incorporate these systems, it’s going to come with brand-new risks,” Hultquist added. “There are certainly threat actors who are ahead of others when it comes to that problem – TeamPCP has been extremely successful.” Since March, TeamPCP has pulled off several very large scale open source supply chain attacks targeting ecosystems including PyPI, npm, and Docker Hub. After compromising these open source packages and registries, TeamPCP, which Google tracks as UNC6780, typically deploys stealers to scoop up cloud and AI system credentials. “Evidence indicates that UNC6780 created a malicious GitHub Actions workflow for the company’s proprietary AI repository, and that the extortion actor exfiltrated a copy of this AI repository,” the report says. “Beyond these demonstrated tactics, UNC6780 has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices.” While Google’s earlier AI tracker, published in February, documented attackers experimenting with agentic AI to support certain pieces of the attack chain, in the past quarter they’ve gone on to integrate agentic capabilities into multiple stages of an attack lifecycle, according to the researchers. In one example, Mandiant observed miscreants who compromised an organization’s cloud infrastructure in an autonomous, multi-agent credential-harvesting attack that took less than six hours. During that time, the agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP rotation logic without manual intervention. “Like scanning – but with a brain,” Hultquist said. In another case detailed in the report, Google Threat Intelligence observed a China-linked espionage group using Gemini to design a dynamic, automated penetration-testing framework that could reason through actions, execute tasks, and change course as needed in unpredictable environments. Google disabled the assets associated with this particular crew. “That’s where we are headed,” Hultquist said. “We're kind of in this interim place where threat actors are inserting agentic AI into certain parts of their operations, but we've not gotten to the place where they are able to sort of remove themselves entirely. We're right on the precipice of that.” ®
Kategorie: Viry a Červi

Microsoft: Windows Server 2025 changes causing app crashes

Bleeping Computer - 8 Září, 2026 - 13:57
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]
Kategorie: Hacking & Security

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News - 8 Září, 2026 - 13:54
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
Kategorie: Hacking & Security

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News - 8 Září, 2026 - 13:54
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

What It Took to Reach 1 Billion Build Manifests

The Hacker News - 8 Září, 2026 - 13:49
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
Kategorie: Hacking & Security

What It Took to Reach 1 Billion Build Manifests

The Hacker News - 8 Září, 2026 - 13:49
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally [email protected]
Kategorie: Hacking & Security

Apple after Cook: The Ternus age begins this week

Computerworld.com [Hacking News] - 8 Září, 2026 - 13:46

We’re hurtling toward the loss of something big. Finally, after months of speculation, Apple is about to introduce its first-ever folding smartphone. And once it does, the conversation will change as the annual iPhone rumor season is replaced with the reality of whatever Apple unveils.

Except, it won’t quite be the same as in the past. Because no sooner will new Apple CEO John Ternus finish his iPhone announcement keynote speech tomorrow than the speculation will shift to next year’s 20th-anniversary iPhone, what’s coming to the iPhone 18 and e-series iPhones, and expectations around Apple’s upcoming wave of smart home products, including health and home security services. There’s a lot going on.

Meet John Ternus

Having a lot going on is one of the prime expectations of Apple under its new boss. A family man with a wife and kids, he’s led Apple’s hardware division for five years after an eight-year stint running hardware engineering. He joined the company in 2001 and is described as a highly competent, hugely talented, and modest by nature. 

His hobby is quite revealing — he drives race cars, is a regular at California’s Laguna Seca Raceway, and owns an incredibly rare 2019 Porsche 935. To me it suggests a calm, competent, individual with excellent mental and physical reflexes who can make life or death decisions at speed. He’s also deeply committed to good product design.

He’ll need that calm embrace of speed and adrenaline to manage the company his predecessor, Tim Cook, led to become the world’s most valuable firm. 

A hard act to follow

He’s also got a hard act to follow, as while Cook had to carve out his reputation in the shadow of Steve Jobs, Ternus must sculpt his own destiny in the shadow of Cook, who managed to make shareholders of record in 2011 around 20 times richer by the time he quit. (Apple stock rose from $13.74 per share on a split adjusted basis to $319.97 per share today.)

While Cook was frequently criticized for not being a product guy, he presided over the launch of the Apple Watch, AirPods, Apple Silicon, and the Vision Pro, and helped grow Apple’s services income to become its second-biggest product category, diversifying Apple’s revenue and creating financial stability. That’s no easy task.

Building his own team

Can Ternus improve on that? He’s certainly being positioned as someone who can. His deep experience in hardware has led to expectations that Apple will double down on product under his watch, so a great deal is expected of him in consequence. He is also putting together a hardware-focused team, including Laura Legros, former vice president of hardware engineering, as a direct report.

What will we see of this tomorrow? To be fair, while he will lead the announcement on the keynote stage, development of this first tranche of products took place under the leadership of Cook, and while Ternus will have had a big hand in development, this year’s Apple event should be seen as a moment of transition. 

“I’m just as excited about what lies beyond that, including the incredible products already in the works and the ones we haven’t even imagined yet that we’ll dream up and create together. There’s no team in the world I’d rather build the future with,” Ternus told Apple staff in his first memo as CEO.

It’s what Apple does in the next couple of years that will truly define the new leadership. He’s literally been CEO for a week!

What to expect on Sept. 9

Here’s my TL; DR list:

  • First folding iPhone: Apple’s response to folding devices from Samsung, Google, Huawei, Xiaomi. It’s expected to have a highly durable, near invisible hinge and a powerful 2nm A20 chip around 20% more performant than the 17 series devices; Touch ID; a 48MP camera; and be able to unfold from a 5.5-in. to a 7.8-in. display. Potentially called iPhone Ultra, some predict it might be the “iPhone Duo” or “iPhone Fold.” It’s likely to cost $2,000+.
  • iPhone 18 Pro series: Equipped with a fantastic new display, smaller Dynamic Island, 48MP main camera, and telescopic lens and supported by a fresh tranche of pro-photography features, the 18 Pro/Pro Max range will also use A20 chips. Both the fold and Pro devices will carry significantly more RAM, enabling them to handle on-device AI tasks. Apple is expected to introduce the iPhone 18, iPhone Air 2, and iPhone 18e devices at a spring 2027 event. Prices on all iPhones are expected to increase by $100 or more, depending on model.
  • Apple Watch Series 12, Apple Watch Ultra 4: While Apple is thought to be working on new designs for next year, this year’s models will — for the first time in years — include an improved processor, better networking, and more accurate heart monitors. A model with a ceramic body is expected, while the devices will be equipped with additional storage, and integrated satellite emergency features. 
  • AirPods 5: Earlier speculation about cameras inside AirPods remains, but these aren’t expected at the launch. Instead, Apple’s AirPods 5 will be boosted with a new H3 Wireless Chip for better voice isolation, noise cancellation, and spatial audio. They may also provide some basic health monitoring features with a built-in temperature sensor and heart rate monitoring.
  • Smart home products: Apple is still expected to introduce additional products for smart homes, including an Apple TV with a faster processor and SiriAI support, a HomePod mini upgrade, and — potentially — a new home hub. The latter could effectively be a combination of an iPad with a HomePod to run apps, control smart devices, take and make calls, and run Siri.
Finding the next big thing

While all these products are important to the company, the smart home devices should demand attention (if they appear at all), as the indicators suggest Apple intends to explore the smart home space with a range of future hardware, including domestic robotics, security services, and smart devices. This hardware proliferation in new markets could end up becoming one of the hallmarks of Ternus’ Apple leadership, as will Apple’s AR spectacles (once they are introduced). 

Equally, it cannot be ignored that one of Ternus’ main tasks since becoming vice president of hardware has been the introduction of new Macs and the transition to Apple Silicon. So he’ll be expected to strike a balance between improving Apple’s traditional product lines while racing his company toward new and emerging opportunities in hardware. (I believe Apple should pay much more attention to the enterprise space within that.) 

Apple’s little AI problem

The biggest challenge to all of this will be Apple’s success in implementing AI that’s good enough to get things done while avoiding the unexpected dangers of poor implementation. We don’t want AI agents corroding smart home security, for example, which is why Ternus seems likely to maintain Cook’s focus on security and privacy as enabling technologies to support trusted hardware/software product designs.

Another thing? Tomorrow’s keynote will likely begin with the single word, “Hello,” and feels very likely to also include that classic Apple keynote line, “…One more thing.”

We’ll find out more as the conversation moves from speculation to reality after the 10am (PT) keynote.

Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Netflix a 30 nejoblíbenějších filmů a seriálů v září 2026

Živě.cz - 8 Září, 2026 - 13:45
Tyto filmy a seriály jsou teď na českém Netflixu nejoblíbenější. Nerozlišujeme žánr, stáří ani hodnocení na filmových webech. Jde o souhrnnou oblíbenost za poslední týdny, kterou zjišťuje web FlixPatrol.
Kategorie: IT News

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

The Hacker News - 8 Září, 2026 - 13:22
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The
Kategorie: Hacking & Security

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

The Hacker News - 8 Září, 2026 - 13:22
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Swiss government explores replacing Microsoft 365 with open-source software

Computerworld.com [Hacking News] - 8 Září, 2026 - 13:10

Swiss authorities have launched a pilot project to determine whether it is possible to replace Microsoft 365 with similar open-source services, RTS reports. This follows a proof-of-concept project in which 172 civil servants tested the German open-source platform openDesk.

According to Matthias Stürmer, a professor at the University of Bern, there are three main reasons for the switch: to reduce dependence on US services, to improve operational reliability, and to reduce costs.

In the first phase, the migration involves 3,000 computers, which corresponds to 7% of Switzerland’s federal workforce. The government has more than 54,000 workstations in operation. The pilot will prioritize employees who have access to highly sensitive data, according to RTS.

A move by the Swiss Armed Forces from Microsoft 365 to openDesk is already underway, with that migration expected to be completed in October, It’s FOSS reports.

Switzerland’s move is part of a larger ‘digital sovereignty’ effort in the European Union that aims to retain local control over data, applications, and infrastructure. In January, lawmakers directed the European Commission to map critical technology dependencies and then develop policies to reduce reliance on foreign providers.

This article originally appeared on Computer Sweden.

More on the EU’s digital sovereignty push:

Kategorie: Hacking & Security

Judge spares Google’s ad-tech business from a breakup

Computerworld.com [Hacking News] - 8 Září, 2026 - 13:00

Back in April 2025, the US Department of Justice (DoJ) proudly proclaimed that it had prevailed in a landmark antitrust case against Google’s ad business. Yeah. Right.

You see, just last week, US District Judge Leonie M. Brinkema rejected the DoJ’s effort to force Google to sell its AdX ad exchange. What began as a major anti-monopoly victory has become a mouse-sized settlement. 

[ Google US antitrust trials: A timeline ]

Does any of this this sound familiar? It should. We’ve seen this show before. Last year, Google had also been convicted of abusing its search business. At first, all the talk was about how Google might be forced to divest itself of the Chrome browser and/or the Android operating system. 

Instead, Google was allowed to keep making search deals and only had to share some search data with its rivals. 

I say rivals, but in fact Google still dominates the search market. Indeed, its control has actually expanded a bit. By StatCounter’s numbers, in August 2025, Google search owned 89.89% of the market. By last month, almost a year after the company had been slapped on the wrist, its share had grown to 91.1%

Boy, wasn’t that a win?

The remedies phase of the government’s ad-tech antitrust case order is a similar Google win. No, it doesn’t overturn the April 2025 finding that Google unlawfully maintained monopolies in the publisher ad-server and ad-exchange markets, or that it illegally tied its ad server and exchange together. Instead, it determines how the company must change its conduct.

The DoJ wanted Google to divest itself of AdX, the company’s ad exchange for matching publisher inventory with advertiser demand. It also sought to require Google to open-source the final-auction logic in its DoubleClick for Publishers (DFP) ad server and, if necessary, divest its DFP business. 

Brinkema rejected all three requests. Instead, her short order accepts “most” of the parties’ proposed behavioral remedies, subject to modifications described in a memorandum opinion that remains sealed while the parties identify confidential information for redaction.

Specifically, the court directed Google and the plaintiffs to meet and submit a joint proposed final judgment within 30 days. If they cannot agree on the details, each side must submit its own proposed version.

Google — as it should — sees this as a win. As Lee-Anne Mulholland, Google’s vice president of regulatory affairs, said in a statement, “We’re very pleased the Court rejected the DOJ’s proposal to break apart tools that help small businesses reach new customers and grow.”

Far less convincing is the DOJ’s characterizing the decision as a win. “The Antitrust Division is pleased that the court ordered substantial relief in the Google ad-tech case. We are one step closer to restoring competition and bringing relief for the American people in online advertising markets.” 

Oh please! It does nothing of the sort.

To quote Laurel Kilgour, research manager at the American Economic Liberties Project, an anti-monopoly, nonprofit group: “Judges keep finding Google guilty, but Google keeps walking away with both its ill-gotten gains and its empire intact. Without actual structural remedies, antitrust rulings are just inconvenient speed bumps that allow Google to lock down search and ad tech markets today while using that same unchecked power to monopolize tomorrow’s AI frontier.

Exactly so. 

The specific obligations Google will face are not yet public, because Brinkema’s explanatory opinion remains under seal. Earlier, Google had proposed making real-time bidding responses from AdX available to rival ad servers, removing Unified Pricing Rules, and accepting a monitoring trustee for a three-year supervision period. None of that will even dent Google’s ad business.  

When all’s said and done, Google is still in charge of both its exchange and publisher ad-server operations. I expect the minor changes required won’t amount to a hill of beans. Restoring competition in markets where the company was found to have used its vertically integrated position unlawfully? Give me a break. 

Public Knowledge, a free speech and internet advocacy group, described the decision as one that leaves Google’s monopoly power substantially intact. 

As Public Knowledge Legal Director John Bergmayer said, “The court found that Google illegally acquired and maintained monopolies in publisher ad servers and ad exchanges, and used its control of DFP and AdX to shut out rivals.” He concluded, “Telling a monopolist to do better is not the same as restoring competition.… A finding of liability means little if the remedy leaves the market fundamentally unchanged.”

Ya think? 

In Google’s last reported quarter, the company reported $81.6 billion in advertising revenue. Next year, when Google is being “punished,” I expect its revenue will be even higher. 

Kategorie: Hacking & Security

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

Computerworld.com [Hacking News] - 8 Září, 2026 - 12:54

A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said.

The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel.

The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK also reported 4,148 captured session cookies and 1,032 plaintext passwords. The firm said 474 records showed completed logins in which attackers captured the authenticated session created after MFA.

BigBear 2.0 is built on Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft’s legitimate authentication service. The victim signs in through the proxied page and completes MFA as usual. Once Microsoft issues an authenticated session cookie, the phishing infrastructure can intercept it and allow the attacker to reuse the session without completing the authentication process again.

The operation also uses residential proxies selected according to the victim’s country, which can make malicious authentication traffic appear geographically consistent with the user. CloudSEK said this technique can weaken location-based checks used in Conditional Access policies.

Researchers also found custom code designed to disable FIDO2/WebAuthn authentication on the phishing pages, potentially steering users toward weaker, phishable authentication methods.

CloudSEK described BigBear 2.0 as a multi-user service with at least five identified affiliate operators. The company said it observed 42 virtual private server (VPS) nodes over the campaign, with 26 deleted from the panel since late July.

IT services and managed service providers accounted for 151 of the organizations identified by CloudSEK, making them the most heavily represented sector in its data. Such organizations can present especially valuable targets because employees may hold privileged access to customer environments and administrative systems.

Session theft moves into the mainstream

The significance of BigBear 2.0 is not just its ability to capture authenticated sessions after MFA, but the way it packages techniques once associated with more skilled attackers into a service that can be used at scale, said Keith Prabhu, founder and CEO of Confidis.

The underlying technique is not new, said Akshat Tyagi, associate practice leader at HFS Research. “What BigBear 2.0 changes is accessibility and scale,” Tyagi said. “It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks.”

That shift means enterprises need to think beyond protecting the authentication event itself, he said, because a captured session may give an attacker access to Microsoft 365 without another password or MFA challenge.

Prabhu added that successful MFA should no longer be treated as proof that an account or session remains secure.

Session cookies and access and refresh tokens should be treated as high-value authentication material rather than technical artifacts behind the password, said Sakshi Grover, senior research manager for cybersecurity products and services at IDC Asia Pacific.

The risk, she said, is that many enterprise controls are still geared toward detecting credential theft rather than the hijacking of an already authenticated session.

Phishing-resistant authentication becomes critical

OTP, SMS, and push-based MFA should not be relied on as standalone defenses against this type of attack, Tyagi said, because the attacker can allow the legitimate user to complete authentication before stealing the resulting session.

Tyagi said enterprises should enforce phishing-resistant authentication such as FIDO2/WebAuthn passkeys rather than merely making it available alongside weaker alternatives. Prabhu pointed to Windows Hello for Business and certificate-based authentication as additional options, with stronger methods enforced through Conditional Access authentication strengths.

Grover said organizations should also use Continuous Access Evaluation and token protection where Microsoft 365 supports them, but cautioned against treating token protection as a complete solution because coverage varies across platforms, clients and workloads.

The problem is also operational, Grover said. Identity and access tools are not always sufficiently integrated with security operations or SIEM platforms, leaving potentially useful identity signals disconnected from the analysts responsible for detecting attacks.

Password resets are not enough

“Treat the event as an active session compromise, not merely a stolen-password incident,” Prabhu said.

He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications.

Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said.

Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added.

Grover said organizations should also include session hijacking in tabletop exercises, testing how identity, security operations, messaging, and cloud teams would coordinate during an authenticated-session compromise. Such exercises can expose gaps that may not emerge in simulations centered on conventional credential theft or ransomware, she said.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Čechům budou chodit balíčky i v sobotu. Víkendové doručování spouští další dopravce

Živě.cz - 8 Září, 2026 - 12:45
GLS začal do svých boxů doručovat balíky i v sobotu. • Aktuálně má 2000 boxů, do půl roku jich bude o polovinu více. • Zásilkovna letos rovněž spustí sobotní doručování.
Kategorie: IT News
Syndikovat obsah