Skip to content
Threat Feed

Product

SharePoint Online

5 briefs RSS
high threat

Passkey-Themed Social Engineering Targeting Microsoft Cloud Identities

Threat actors are using passkey-themed phishing and adversary-in-the-middle attacks to compromise Microsoft cloud accounts, establish persistent access via registered MFA methods, and exfiltrate data via Microsoft Graph API.

SharePoint Online +3 UNC6671 phishing cloud-security credential-harvesting mfa-bypass data-exfiltration
3t 10i
medium advisory

Detection of Unusual OAuth Application Access to SharePoint and OneDrive

This brief details a detection strategy for identifying potential OAuth phishing and illicit consent grants by monitoring for first-time application access to Microsoft 365 file storage.

SharePoint Online +1 cloud identity oauth phishing collection
1r 2t
high advisory

Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices

Attackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.

Microsoft 365 +4 cloud saas identity microsoft-365 initial-access phishing persistence
2r 3t
high advisory

O365 Security Compliance Alerting for Potential Ransomware Activity

This brief focuses on detecting potential ransomware activity within Microsoft Office 365 environments by monitoring security and compliance alerts, aiding in early identification and mitigation of ransomware threats.

Office 365 +2 ransomware o365 cloud
3r 3t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t