Microsoft has been published a very good summary about security trends in 2023 which considered post authentication attacks, such as : microsoft.com/en-us/security/b

If you are interested to learn more about Token replay attacks, check the following blogs:

🔗 Token tactics: How to prevent, detect, and respond to cloud token theft by Microsoft DART team: microsoft.com/en-us/security/b

This article describes Adversary-in-the-middle (AitM) phishing/Pass-the-cookie attack scenarios and recommendations.

🔗 Abuse and replay of Azure AD refresh token from Microsoft Edge in macOS Keychain:
cloud-architekt.net/abuse-and-

I've written this blog post about token replay on devices last year. It covers an attack scenario to exfiltrate tokens from Keychain which is used to store cached Azure AD tokens for “logged in” Edge profiles on macOS devices.

🔗 Azure AD Attack & Defense: Replay of Primary Refresh (PRT) and other issued tokens from an Azure AD joined device:
github.com/Cloud-Architekt/Azu

A comprehensive overview about attack and defense scenarios primary refresh token (PRT) & other tokens on Windows has been published by Sami Lamppu and and me. The article includes many references and links to other community resources around this topic.

#azuread #tokentheft #macos

Last updated 3 years ago

Thomas Avedik :verified: · @avedik
110 followers · 310 posts · Server mastodon.world

@datenschutzbochum

"Threat actors are stealing tokens already verified by multifactor authentication (MFA) to breach organizations' systems"

Seems to be a pretty nasty attack as organizations haven't considered as part of their response plan....đŸ€š

#authentication #tokentheft #INCIDENT #cybersecurity #cyberattack #mfa #microsoft

Last updated 3 years ago

Strömblad · @nopatience
7 followers · 42 posts · Server swecyb.com

Sedan nÄgra mÄnader tillbaka har jag genomfört en förelÀsning om InfoStealers dÀr jag försöker utan teknikskt djup förklara hur marknaden fungerar för "loggar". Det handlar om sammanflÀtningen av vÄra privata och professionella liv.

Hur som helst.

Microsoft har publicerat en artikel pÄ Àmnet ganska nyligen som tar upp det hÀr Àmnet men frÄn ett tekniskt perspektiv. Bra artikel.

microsoft.com/en-us/security/b

#microsoft #tokentheft #infostealer

Last updated 3 years ago