BigBear phishing crew nets thousands of Microsoft 365 credentials

https://image.theregister.com/5294968.jpg?imageId=5294968&x=0&y=8.84&cropw=100&croph=78.66&panox=0&panoy=8.84&panow=100&panoh=78.66&width=1200&height=683

Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations

A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel.

Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving them an unusually detailed look at the campaign and its haul.

According to the researchers, the panel contained 5,137 records associated with 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies. CloudSEK classified 474 records as complete MFA-bypassed authentications in which the attackers captured an authenticated Microsoft 365 session.

That potentially hands the crooks much more than an inbox. A hijacked Microsoft 365 account can expose email, calendars, Teams conversations, and files stored...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1920-80.jpg

‘I also want to feel the frontier’ — Gemini users are starting to think that Gemini Pro 4 won’t ever see the light of day thanks to the release of ChatGPT 6 Astra and Claude Fable 5.1

Being a devoted Gemini user seems to require a peculiar combination of loyalty, patience, and an unusually high tolerance for the word Flash. That patience is being tested again. Anthropic released Claude Fable 5.1 last week, bringing significant improvements to its model lineup. OpenAI followed with GPT-6 Astra, its