build1 publisher
A passkey 'upgrade' call ends with the attacker's phone number registered as an MFA method
Microsoft Security Research describes callers posing as IT staff to get a Microsoft 365 session relayed or minted to their own client. The lasting damage comes from the MFA method they then register.
Publishers:dev.to
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence55