시가총액: $2.1826T -1.93%
거래량(24시간): $56.1969B -8.13%
  • 시가총액: $2.1826T -1.93%
  • 거래량(24시간): $56.1969B -8.13%
  • 공포와 탐욕 지수:
  • 시가총액: $2.1826T -1.93%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

전문가들은 새로운 피싱 및 OAuth 악용으로 인해 Microsoft 365 보안이 위협받고 있다고 경고합니다.

2026/02/08 13:34

OAuth 결함을 활용하여 Microsoft 365 방어를 우회하고 지속적인 계정 액세스 권한을 얻는 피싱 공격이 진화하고 있습니다. 최신 위협과 자신을 보호하는 방법에 대해 알아보세요.

전문가들은 새로운 피싱 및 OAuth 악용으로 인해 Microsoft 365 보안이 위협받고 있다고 경고합니다.

New Phishing and OAuth Exploits Threaten Microsoft 365 Security, Experts Warn

전문가들은 새로운 피싱 및 OAuth 악용으로 인해 Microsoft 365 보안이 위협받고 있다고 경고합니다.

In a concerning development for digital security, a new wave of sophisticated attacks is targeting Microsoft 365 accounts by cleverly combining phishing tactics with vulnerabilities in OAuth authentication tokens. Cybersecurity researchers are sounding the alarm, highlighting how attackers are chaining seemingly minor web flaws with advanced social engineering to bypass traditional security measures and gain persistent access to sensitive cloud services.

우려스러운 디지털 보안 개발 과정에서 피싱 전술과 OAuth 인증 토큰의 취약성을 교묘하게 결합하여 Microsoft 365 계정을 표적으로 삼는 새로운 정교한 공격이 등장하고 있습니다. 사이버 보안 연구원들은 공격자가 전통적인 보안 조치를 우회하고 민감한 클라우드 서비스에 지속적으로 액세스하기 위해 고급 사회 공학을 통해 사소해 보이는 웹 결함을 연결하는 방법을 강조하면서 경고를 울립니다.

The Evolving Phishing Landscape

진화하는 피싱 환경

Email continues to be a primary vector for cyberattacks, but with enhanced filters and authentication protocols like SPF and DMARC, traditional phishing methods are becoming less effective. Attackers have adapted by exploiting legitimate business logic and web application features. Researchers have identified methods where attackers manipulate input fields in public-facing API endpoints. This allows them to trick an organization's own infrastructure into sending malicious emails that, because they originate from authorized servers, bypass security checks and land directly in the victim's inbox. This technique cleverly leverages the inherent trust in an organization's domain.

이메일은 계속해서 사이버 공격의 주요 벡터가 되고 있지만 SPF 및 DMARC와 같은 향상된 필터와 인증 프로토콜을 사용하면 기존 피싱 방법의 효율성이 떨어지고 있습니다. 공격자는 합법적인 비즈니스 논리와 웹 애플리케이션 기능을 악용하여 적응했습니다. 연구원들은 공격자가 공개 API 엔드포인트의 입력 필드를 조작하는 방법을 식별했습니다. 이를 통해 조직의 자체 인프라를 속여 악성 이메일을 보내도록 할 수 있습니다. 악성 이메일은 승인된 서버에서 발송되기 때문에 보안 검사를 우회하여 피해자의 받은 편지함에 직접 도착합니다. 이 기술은 조직 도메인에 내재된 신뢰를 교묘하게 활용합니다.

OAuth Token Abuse: A New Frontier

OAuth 토큰 남용: 새로운 개척지

A significant part of this new threat lies in the abuse of OAuth 2.0 tokens. These tokens function as trusted credentials, allowing services to access user accounts without requiring passwords, often seen in features like "Continue with Microsoft." However, attackers are tricking users into granting these access tokens to attacker-controlled applications through malicious phishing emails. Once an attacker possesses a valid OAuth token, they can access sensitive data such as emails, files, and calendars. Crucially, traditional security measures like changing passwords or enabling multi-factor authentication (MFA) do not automatically revoke these tokens, allowing attackers to maintain access until the token is manually revoked or expires. This can lead to full account takeovers and lateral movement within corporate networks.

이 새로운 위협의 중요한 부분은 OAuth 2.0 토큰의 남용에 있습니다. 이러한 토큰은 신뢰할 수 있는 자격 증명으로 작동하여 서비스에서 암호를 요구하지 않고 사용자 계정에 액세스할 수 있도록 하며, "Microsoft를 계속 사용"과 같은 기능에서 자주 볼 수 있습니다. 그러나 공격자는 악성 피싱 이메일을 통해 사용자를 속여 공격자가 제어하는 ​​애플리케이션에 이러한 액세스 토큰을 부여하도록 합니다. 공격자가 유효한 OAuth 토큰을 소유하게 되면 이메일, 파일, 달력과 같은 민감한 데이터에 접근할 수 있습니다. 결정적으로, 비밀번호 변경이나 다단계 인증(MFA) 활성화와 같은 기존 보안 조치는 이러한 토큰을 자동으로 취소하지 않으므로 공격자가 토큰을 수동으로 취소하거나 만료될 때까지 액세스를 유지할 수 있습니다. 이는 기업 네트워크 내에서 전체 계정 탈취 및 측면 이동으로 이어질 수 있습니다.

Weaponizing Device Codes and API Flaws

장치 코드 및 API 결함 무기화

Recent campaigns have specifically highlighted the weaponization of OAuth device code flows, a feature designed for devices with limited input capabilities. Attackers send phishing messages with URLs or QR codes that initiate an OAuth grant on a legitimate login page. When victims enter the displayed code, believing it to be safe, attackers receive the OAuth access token tied to their account. Furthermore, a specific attack chain involves pairing this email flaw with improper error handling in cloud environments. When applications display verbose errors for debugging, malformed requests can inadvertently leak sensitive authentication tokens, like JSON Web Tokens (JWTs) used for Microsoft Graph API communication, alongside stack traces. These tokens grant immediate, authenticated access without triggering login alerts.

최근 캠페인에서는 입력 기능이 제한된 장치를 위해 설계된 기능인 OAuth 장치 코드 흐름의 무기화를 특히 강조했습니다. 공격자는 합법적인 로그인 페이지에서 OAuth 권한 부여를 시작하는 URL 또는 QR 코드가 포함된 피싱 메시지를 보냅니다. 피해자가 안전하다고 믿고 표시된 코드를 입력하면 공격자는 자신의 계정에 연결된 OAuth 액세스 토큰을 받습니다. 또한 특정 공격 체인에는 이 이메일 결함과 클라우드 환경의 부적절한 오류 처리가 결합되어 있습니다. 애플리케이션이 디버깅을 위해 자세한 오류를 표시하는 경우 잘못된 형식의 요청으로 인해 스택 추적과 함께 Microsoft Graph API 통신에 사용되는 JWT(JSON 웹 토큰)와 같은 민감한 인증 토큰이 실수로 유출될 수 있습니다. 이러한 토큰은 로그인 경고를 트리거하지 않고 즉시 인증된 액세스 권한을 부여합니다.

Defending Against the Threat

위협으로부터 방어

To combat these evolving threats, cybersecurity experts recommend several key strategies. Organizations must enforce strict input validation on all public APIs to ensure they only accept the minimum necessary parameters. Production environments should be configured to return generic error messages, suppressing detailed debug information that could leak credentials. While standard OAuth 2.0 is a backbone for API security, its limitations in scenarios requiring person-to-person delegation are becoming apparent. Solutions like User-Managed Access (UMA) 2.0, which adds a centralized policy layer to OAuth, are gaining traction for enabling more granular and secure sharing. Ultimately, staying vigilant, educating users about phishing risks, and implementing robust API security and error handling practices are paramount in safeguarding Microsoft 365 accounts and other cloud services.

이렇게 진화하는 위협에 맞서기 위해 사이버 보안 전문가는 몇 가지 핵심 전략을 권장합니다. 조직은 최소한의 필수 매개변수만 허용하도록 모든 공개 API에 대해 엄격한 입력 검증을 시행해야 합니다. 프로덕션 환경은 일반 오류 메시지를 반환하고 자격 증명이 유출될 수 있는 자세한 디버그 정보를 억제하도록 구성되어야 합니다. 표준 OAuth 2.0은 API 보안의 백본이지만 개인 간 위임이 필요한 시나리오에서는 한계가 분명해지고 있습니다. OAuth에 중앙 집중식 정책 계층을 추가하는 UMA(사용자 관리 액세스) 2.0과 같은 솔루션은 보다 세부적이고 안전한 공유를 가능하게 하기 위해 주목을 받고 있습니다. 궁극적으로 경계를 늦추지 않고 사용자에게 피싱 위험에 대해 교육하고 강력한 API 보안 및 오류 처리 방법을 구현하는 것은 Microsoft 365 계정 및 기타 클라우드 서비스를 보호하는 데 가장 중요합니다.

So, while the digital world keeps throwing new curveballs, a little awareness and some solid security hygiene can go a long way. Stay safe out there, and maybe think twice before clicking that link!

따라서 디지털 세계가 계속해서 새로운 변화를 가져오는 동안 약간의 인식과 견고한 보안 위생이 큰 도움이 될 수 있습니다. 안전하게 지내세요. 링크를 클릭하기 전에 다시 한 번 생각해 보세요!

원본 소스:the420

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月26日 에 게재된 다른 기사