.

Jul 12, 2026 2:19 AM

Hackers are using fake Microsoft Entra passkey pages to target Microsoft 365 accounts.

The vishing campaign steals credentials and MFA responses, then attempts to register attacker-controlled passkeys while adapting to prompts in real time.

Read how the attack works: https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html

current_events

hacker

microsoft

news

wow

I don’t understand what any of those words mean, but I also don’t have Microsoft 365.

2 months ago | Likes 16 Dislikes 0

Hackers (it's actually scammers using social engineering) have created a fake login page, and fooled regular users into clicking on phishing links to get then there. When the users try to login, the scammers just take the account information they used to steal the accounts.

It's being reported as something rare, but it's the most common kind of attack known to date. It's the "your account is about to be terminated!" spam emails you probably get every couple of weeks.

2 months ago | Likes 9 Dislikes 0

TIL: Cisco says "Vishing, short for voice phishing, refers to fraudulent phone calls or voice messages designed to trick victims into providing sensitive information, like login credentials, credit card numbers, or bank details. "

2 months ago | Likes 10 Dislikes 0

Yeah there is phishing, vishing, and smishing

2 months ago | Likes 2 Dislikes 0

Oh. If someone calls me and I don’t know who they are, then no matter who they claim to be I just repeat “Fuck off, I don’t know you.” Until they get bored and hang up. I’ve automated it so I don’t have to do it manually, my phone just plays it on loop.

2 months ago | Likes 6 Dislikes 0