Security News > 2020 > July > Microsoft warns organizations of consent phishing attacks

Microsoft warns organizations of consent phishing attacks
2020-07-09 17:21

In this type of phishing campaign, attackers trick people into giving a malicious app consent to access sensitive data, says Microsoft.

A more specialized type of campaign known as consent phishing aims to grab sensitive data not by snagging your password but by tricking you into giving the necessary permissions to a malicious app.

Further, Microsoft is trying to better secure its application ecosystems by allowing customers to set policies on the types of apps to which users can give certain consent.

To help protect against consent phishing campaigns, Microsoft offers advice for individuals and organizations.

Attackers like to spoof app names that make it appear to come from legitimate applications or companies but drive you to consent to a malicious app.


News URL

https://www.techrepublic.com/article/microsoft-warns-organizations-of-consent-phishing-attacks/#ftag=RSS56d97e7

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 49 1366 2822 162 4399