#eviltokens — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.
-
Notion Abused to Harvest Authentication Tokens in Targeted Attacks
Researchers uncovered a sneaky phishing campaign where attackers abused Notion to steal authentication tokens, using free accounts to impersonate senior executives and send legit-looking document-sharing notifications. This clever tactic was linked to two phishing-as-a-service platforms and over 600 malicious scripts.
#Phishingasaservice #Eviltokens #Tycoon2fa #CollaborationPlatformAbuse #Notion
-
OAuth Grants Expose Hidden Risk Below MFA Perimeter
In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and…
#OauthSecurityRisk #Phishingasaservice #MfaBypass #Eviltokens #Microsoft365