Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Sources: AI training startup Mercor eyes $10B+ valuation on $450 million run rate

Mistral and ASML forge €1.7bn alliance to shape Europe’s AI future

Easier Painting Than Thinking: Can Text-to-Image Models Set the Stage, but Not Direct the Play? – Takara TLDR

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
MIT News

Def Con 34: Phishing as a Service – mit Microsoft

By Advanced AI EditorAugust 12, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


This is how easily Keanu Nys from Spotit in Belgium modified Microsoft’s online login website. Since Microsoft also enables its EntraID as a universal login via various tenants and continues to transmit the password as plain text, the researcher has built a phishing platform from the official login. This is to obtain the login data of any user.

The trick is that the ability to customize the login page via CSS and display your own images makes it easy to capture even MFA authentications. Here, too, it is clear that Microsoft has made far too many compromises harming security and in favor of more features, thereby making the entire MFA system unidentifiable for end users or open to phishing attacks against their Microsoft ID.

How to fall for micro-oft.com

Specifically, Nys showed in his Def-Con presentation that users can easily be fooled by the tenant through simple CSS customization, custom fonts and the display of images on the login page. “micro-oft.com” becomes “microsoft.com” by replacing the hyphen in the font with an “s”.

Attackers can then use Pass Through Authentication (PTA) to check whether the captured access data is valid and whether they have captured a session ID with which they can use all the tenant’s services (M365, storage and more). Even MFA is no obstacle here: You simply pre-generate all “99” possible requests and can then integrate them via an image. However, this requires two tenants.

All “phishing attempts” come from the official Microsoft domain. This means that they cannot be stopped by firewalls, DNS filters and similar security measures. It is difficult to imagine how Microsoft intends to prevent these attacks. The only way out is to shut down several functions and finally switch to secure functions.

(dmk)

Don’t miss any news – follow us on
Facebook,
LinkedIn or
Mastodon.

This article was originally published in

German.

It was translated with technical assistance and editorially reviewed before publication.

Dieser Link ist leider nicht mehr gültig.

Links zu verschenkten Artikeln werden ungültig,
wenn diese älter als 7 Tage sind oder zu oft aufgerufen wurden.

Sie benötigen ein heise+ Paket, um diesen Artikel zu lesen. Jetzt eine Woche unverbindlich testen – ohne Verpflichtung!



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLiquid AI’s LFM2-VL gives smartphones small AI vision models
Next Article Senators urge U.S. probe into DeepSeek data concerns
Advanced AI Editor
  • Website

Related Posts

MIT professor’s AI tools to predict breast and lung cancer risk get her recognized in TIME

September 9, 2025

MIT sees ‘significant new financial pressures’ from Trump cuts

September 9, 2025

MIT Sloan Management Review Research Points to New R&D Framework in Light of Restrictive Immigration Policies

September 9, 2025

Comments are closed.

Latest Posts

Leon Black and Leslie Wexner’s Letters to Jeffrey Epstein Released

Anne Imhof Reimagines Football Jerseys with Nike

Jason Wu, Robert Rauschenberg Collaboration for New York Fashion Week

Storied Collector and MoMA Trustee Dies at 92

Latest Posts

Sources: AI training startup Mercor eyes $10B+ valuation on $450 million run rate

September 10, 2025

Mistral and ASML forge €1.7bn alliance to shape Europe’s AI future

September 10, 2025

Easier Painting Than Thinking: Can Text-to-Image Models Set the Stage, but Not Direct the Play? – Takara TLDR

September 10, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Sources: AI training startup Mercor eyes $10B+ valuation on $450 million run rate
  • Mistral and ASML forge €1.7bn alliance to shape Europe’s AI future
  • Easier Painting Than Thinking: Can Text-to-Image Models Set the Stage, but Not Direct the Play? – Takara TLDR
  • OpenAI could leave California in last-ditch effort to avoid political scrutiny
  • Real-time data activation: Reltio gets better business insights

Recent Comments

  1. zestylizard7Nalay on MIT’s Xstrings facilitates 3D printing parts with embedded actuation | VoxelMatters
  2. fluffymantis7Nalay on MIT’s Xstrings facilitates 3D printing parts with embedded actuation | VoxelMatters
  3. whimsyslug8Nalay on Marc Raibert: Boston Dynamics and the Future of Robotics | Lex Fridman Podcast #412
  4. whackypenguin6Nalay on MIT’s Xstrings facilitates 3D printing parts with embedded actuation | VoxelMatters
  5. zestylizard7Nalay on Ballet Tech Forms The Future Through Dance

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.