Skip to main content

We've updated our Privacy Policy. Questions? Email us any time at privacy@ground.news

Published loading...Updated

Microsoft Passkeys Under Siege: How Vishing Attackers Turn Security Upgrades Into Account Takeovers

Summary by WebProNews
Threat actors have found a clever way to flip a Microsoft security feature on its head. They now use fake Entra passkey enrollment pages to hijack Microsoft 365 accounts. The tactic relies on voice calls that sound official. Victims get told their account needs an urgent security upgrade. Okta first spotted the activity. It tracks the group as O-UNC-066. The actor targets companies across food and beverage, technology, healthcare, automotive, co…
DisclaimerRead with caution - this story is only being covered by one news source that has a ‘low factuality’ rating, which means the outlet has a history of poor reporting practices. Learn more about factuality ratings here.

5 Articles

Microsoft Entra's access keys have been promoted as one of the safest technologies to replace passwords and reduce phishing attacks. However, Okta researchers have identified a sophisticated campaign that shows that although passkeys are resistant to traditional credential theft, they can still be exploited when criminals manage to manipulate the victim through social engineering. The new coup combines vishing (phishing by voice), a real-time ph…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Friday, July 10, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal