AINewsnow

Passkey-themed phishing attacks lead to Microsoft 365 data theft

This story is from 2026-09-12. It is preserved in the archive; the latest stories are on the live feed.

Researchers documented a phishing campaign that impersonated passkey registration prompts, captured live session tokens after users authenticated through legitimate MFA flows, and then used those tokens to access Microsoft 365 tenants with full account privileges (Bleeping Computer). Victims had no…

Read the full story at r/deeplearning ↗

Timeline · 1 report

  1. 2026-09-12 22:37 · r/deeplearning
    Passkey-themed phishing attacks lead to Microsoft 365 data theft

More stories

  1. Microsoft exec called AI scraping the “largest theft of labor in human history” — Ars Technica AI
  2. OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web — The Verge AI
  3. Implementing defense-in-depth authorization for MCP tools on Amazon Quick — AWS Machine Learning Blog
  4. OpenAI's latest AI revelation is a 'serious situation,' Microsoft's Suleyman tells CNBC — CNBC Technology
  5. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  6. Uncontrolled AI could lead to 'silicon species' rivalling humans, warns Microsoft — BBC Technology
  7. Deployed Qwen 3.6 35B A3B on a single DGX Spark supporting 12 concurrent users at 262K context. Are there better ways to optimize this? — r/LocalLLM
  8. Sources: the USPTO and US Copyright Office were surprised by the DOJ's brief supporting OpenAI and Microsoft in their dispute with the New York Times (Axios) — Techmeme

Get the daily brief of stories like this at 6:30 every morning →