時価総額: $2.1851T -1.50%
ボリューム(24時間): $59.2841B -0.55%
  • 時価総額: $2.1851T -1.50%
  • ボリューム(24時間): $59.2841B -0.55%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.1851T -1.50%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

新たなフィッシングと OAuth エクスプロイトが Microsoft 365 のセキュリティを脅かすと専門家が警告

2026/02/08 13:34

フィッシング攻撃は進化しており、OAuth の欠陥を利用して Microsoft 365 の防御を回避し、永続的なアカウント アクセスを取得します。最新の脅威と身を守る方法について学びましょう。

新たなフィッシングと OAuth エクスプロイトが Microsoft 365 のセキュリティを脅かすと専門家が警告

New Phishing and OAuth Exploits Threaten Microsoft 365 Security, Experts Warn

新たなフィッシングと OAuth エクスプロイトが Microsoft 365 のセキュリティを脅かすと専門家が警告

In a concerning development for digital security, a new wave of sophisticated attacks is targeting Microsoft 365 accounts by cleverly combining phishing tactics with vulnerabilities in OAuth authentication tokens. Cybersecurity researchers are sounding the alarm, highlighting how attackers are chaining seemingly minor web flaws with advanced social engineering to bypass traditional security measures and gain persistent access to sensitive cloud services.

デジタル セキュリティの動向が憂慮される中、フィッシング戦術と OAuth 認証トークンの脆弱性を巧みに組み合わせた、Microsoft 365 アカウントをターゲットにした高度な攻撃の新たな波が起きています。サイバーセキュリティ研究者らは、攻撃者がどのようにして一見軽微な Web の欠陥を高度なソーシャル エンジニアリングと連鎖させて、従来のセキュリティ対策を回避し、機密性の高いクラウド サービスへの永続的なアクセスを獲得しているかを強調し、警鐘を鳴らしています。

The Evolving Phishing Landscape

進化するフィッシングの現状

Email continues to be a primary vector for cyberattacks, but with enhanced filters and authentication protocols like SPF and DMARC, traditional phishing methods are becoming less effective. Attackers have adapted by exploiting legitimate business logic and web application features. Researchers have identified methods where attackers manipulate input fields in public-facing API endpoints. This allows them to trick an organization's own infrastructure into sending malicious emails that, because they originate from authorized servers, bypass security checks and land directly in the victim's inbox. This technique cleverly leverages the inherent trust in an organization's domain.

電子メールは引き続きサイバー攻撃の主要なベクトルですが、SPF や DMARC などの強化されたフィルターや認証プロトコルにより、従来のフィッシング手法は効果が薄れてきています。攻撃者は、正規のビジネス ロジックと Web アプリケーションの機能を悪用することで適応してきました。研究者らは、攻撃者が公開 API エンドポイントの入力フィールドを操作する方法を特定しました。これにより、組織のインフラストラクチャを騙して悪意のある電子メールを送信させることができます。この電子メールは、許可されたサーバーから発信されるため、セキュリティ チェックを回避し、被害者の受信箱に直接到達します。この手法は、組織のドメインに固有の信頼を巧みに利用します。

OAuth Token Abuse: A New Frontier

OAuth トークンの悪用: 新たなフロンティア

A significant part of this new threat lies in the abuse of OAuth 2.0 tokens. These tokens function as trusted credentials, allowing services to access user accounts without requiring passwords, often seen in features like "Continue with Microsoft." However, attackers are tricking users into granting these access tokens to attacker-controlled applications through malicious phishing emails. Once an attacker possesses a valid OAuth token, they can access sensitive data such as emails, files, and calendars. Crucially, traditional security measures like changing passwords or enabling multi-factor authentication (MFA) do not automatically revoke these tokens, allowing attackers to maintain access until the token is manually revoked or expires. This can lead to full account takeovers and lateral movement within corporate networks.

この新たな脅威の重要な部分は、OAuth 2.0 トークンの悪用にあります。これらのトークンは信頼できる資格情報として機能し、サービスがパスワードを要求せずにユーザー アカウントにアクセスできるようにします。これは、「Continue with Microsoft」などの機能でよく見られます。ただし、攻撃者は、悪意のあるフィッシングメールを通じてユーザーをだまして、攻撃者が制御するアプリケーションにこれらのアクセス トークンを付与させています。攻撃者が有効な OAuth トークンを所有すると、電子メール、ファイル、カレンダーなどの機密データにアクセスできます。重要なのは、パスワードの変更や多要素認証 (MFA) の有効化などの従来のセキュリティ対策では、これらのトークンが自動的に取り消されないため、トークンが手動で取り消されるか有効期限が切れるまで、攻撃者がアクセスを維持できることです。これにより、アカウントの完全乗っ取りや企業ネットワーク内での水平移動が発生する可能性があります。

Weaponizing Device Codes and API Flaws

武器化されたデバイス コードと API の欠陥

Recent campaigns have specifically highlighted the weaponization of OAuth device code flows, a feature designed for devices with limited input capabilities. Attackers send phishing messages with URLs or QR codes that initiate an OAuth grant on a legitimate login page. When victims enter the displayed code, believing it to be safe, attackers receive the OAuth access token tied to their account. Furthermore, a specific attack chain involves pairing this email flaw with improper error handling in cloud environments. When applications display verbose errors for debugging, malformed requests can inadvertently leak sensitive authentication tokens, like JSON Web Tokens (JWTs) used for Microsoft Graph API communication, alongside stack traces. These tokens grant immediate, authenticated access without triggering login alerts.

最近のキャンペーンでは、入力機能が制限されたデバイス向けに設計された機能である OAuth デバイス コード フローの兵器化が特に強調されています。攻撃者は、正規のログイン ページで OAuth 付与を開始する URL または QR コードを含むフィッシング メッセージを送信します。被害者が表示されたコードを安全だと信じて入力すると、攻撃者はそのアカウントに関連付けられた OAuth アクセス トークンを受け取ります。さらに、特定の攻撃チェーンには、この電子メールの欠陥とクラウド環境での不適切なエラー処理が組み合わされています。アプリケーションがデバッグ用の詳細なエラーを表示すると、不正な形式の要求により、Microsoft Graph API 通信に使用される JSON Web トークン (JWT) などの機密認証トークンがスタック トレースとともに誤って漏洩する可能性があります。これらのトークンは、ログイン アラートをトリガーすることなく、即時の認証されたアクセスを許可します。

Defending Against the Threat

脅威に対する防御

To combat these evolving threats, cybersecurity experts recommend several key strategies. Organizations must enforce strict input validation on all public APIs to ensure they only accept the minimum necessary parameters. Production environments should be configured to return generic error messages, suppressing detailed debug information that could leak credentials. While standard OAuth 2.0 is a backbone for API security, its limitations in scenarios requiring person-to-person delegation are becoming apparent. Solutions like User-Managed Access (UMA) 2.0, which adds a centralized policy layer to OAuth, are gaining traction for enabling more granular and secure sharing. Ultimately, staying vigilant, educating users about phishing risks, and implementing robust API security and error handling practices are paramount in safeguarding Microsoft 365 accounts and other cloud services.

こうした進化する脅威に対抗するために、サイバーセキュリティの専門家はいくつかの重要な戦略を推奨しています。組織は、すべてのパブリック API に対して厳格な入力検証を実施し、必要な最小限のパラメーターのみを受け入れるようにする必要があります。運用環境は、一般的なエラー メッセージを返し、資格情報が漏洩する可能性のある詳細なデバッグ情報を抑制するように構成する必要があります。標準の OAuth 2.0 は API セキュリティのバックボーンですが、個人間の委任が必要なシナリオにおける制限が明らかになりつつあります。 OAuth に集中ポリシー層を追加するユーザー管理アクセス (UMA) 2.0 のようなソリューションは、よりきめ細かく安全な共有を可能にするために注目を集めています。結局のところ、Microsoft 365 アカウントやその他のクラウド サービスを保護するには、警戒を怠らず、フィッシングのリスクについてユーザーに教育し、堅牢な API セキュリティとエラー処理の実践を実装することが最も重要です。

So, while the digital world keeps throwing new curveballs, a little awareness and some solid security hygiene can go a long way. Stay safe out there, and maybe think twice before clicking that link!

したがって、デジタル世界が新たな変化球を投げ続ける一方で、少しの意識と確かなセキュリティ衛生が大いに役立つ可能性があります。安全を確保し、リンクをクリックする前によく考えてください。

オリジナルソース:the420

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月26日 に掲載されたその他の記事