Minacce · 138 giorni fa
La vera rottura non è il bypass MFA in sé. Una volta che UNC6671 entra in Okta o Microsoft 365, usa quell’accesso come punto di lancio per la raccolta di file cloud tramite script e ad alto volume che appare come attività legittima post-login finché i dati non sono già spariti.
1 fonte che coprono questa storia
Welcome to BlackFile: Inside a Vishing Extortion Operation | Google Cloud Blog
UNC6671 leverages vishing combined with victim-branded credential harvesting sites to compromise SSO accounts and capture MFA.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-16