Microsoft has issued a warning about a surge in tax-themed email attacks using PDFs and QR codes to deliver malware. As Tax Day approaches in the United States on April 15, cybercriminals are increasingly targeting individuals and businesses by leveraging tax-related themes to trick users into revealing sensitive information or infecting systems with malicious software. […]
The Microsoft device code phishing attack is a sophisticated cyber threat that manipulates the OAuth device authorization flow to bypass multi-factor authentication (MFA) and gain unauthorized access to Microsoft 365 accounts. According to recent cybersecurity reports, over 55% of phishing attacks in 2024 have targeted Microsoft 365 users, emphasizing the growing vulnerability of cloud-based authentication […]
Update, Feb.10, 2025: This story, first published on February 4, has been updated with insights from a security expert who compares the ease of executing these attacks to assembling flat-pack furniture. Furthermore, it includes new Gmail security recommendations from Google to help mitigate these threats. Gmail security has come under threat as cybercriminals employ artificial […]