Microsoft SharePoint exploited to hack multiple energy firms



  • Hackers exploit SharePoint emails to steal credentials from large energy firms
  • Attackers establish persistence with inbox rules and MFA tampering to maintain access
  • Microsoft advises conditional access policies and phishing-resistant MFA for defense

Hackers are, once again, using SharePoint to target large energy firms, steal employee email credentials, and propagate the attack further.

This is according to a new report from Microsoft, which claims “multiple” large organizations in the energy sector were already targeted.


https://cdn.mos.cms.futurecdn.net/CT482eMSRL8PagRtuBVYNd-2000-80.jpeg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img