Hackers steal Microsoft logins using legitimate ADFS redirects
Hackers are using a novel technique that combines legitimateoffice.com links with Active Directory Federation Services (ADFS) to redirect users to a phishing page that steals Microsoft 365 logins. The method lets attackers bypass traditional URL-based detection and the multi-factor authentication process by leveraging a trusted domain on Microsoft’s infrastructure for the initial redirect. Legitimacy of … Ler mais