Microsoft Exchange Hack

Microsoft says a threat actor gained access to cloud tenants hosting Microsoft Exchange servers in credential stuffing attacks, with the end goal of deploying malicious OAuth applications and sending phishing emails. The attacker then used this inbound connector and transport rules designed to help evade detection to deliver phishing emails through the compromised Exchange servers.

This article has been indexed from Information Security Buzz

Read the original article:

Liked it? Take a second to support IT Security News on Patreon!
Become a patron at Patreon!