Saturday 08 August 2026 12:30:21 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Microsoft login


When a Real Microsoft Login Becomes the Trap Door

Published: 05 August 2026 17:41Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit tied to Kali365 is abusing Microsoft’s device-code sign-in path, showing how legitimate authentication can be twisted into a cloud access problem.

Hotel Wi-Fi, Real Microsoft Pages, and the MFA Trap Behind Device Code Phishing

Published: 03 August 2026 14:34Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A described campaign ties hostile Wi-Fi conditions to a Microsoft login flow that can turn ordinary user approval into cloud access, showing why identity controls now matter as much as network trust.

Guest Wi-Fi Turned Identity Trap: The Hidden Risk Behind Midnight Blizzard’s Latest Move

Published: 03 August 2026 12:13Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A reported campaign tied to public Wi-Fi gateways shows how a wireless foothold in hospitality can turn into stolen Microsoft logins and cloud exposure.

The Fake Microsoft Page That Chases the Session, Not Just the Password

Published: 22 July 2026 12:06Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.

When a Fake Microsoft Login Starts Looking Legit: The Kratos Credential Trap

Published: 16 July 2026 10:11Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

The reported kit blends a brand clone, a Turnstile checkpoint, and bare PHP endpoints into a compact phishing pipeline built to collect enterprise logins.

The Real Microsoft Login That Handed Criminals a Session

Published: 08 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.

Bluekit and the New Login Trap: When Phishing Starts Acting Like a Service Platform

Published: 26 June 2026 17:03Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A fast-moving phishing kit is being watched as it shifts from early testing to live deployment, with Microsoft sign-ins in its sights and proxy-style attacks at the center of the risk.