meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Don’t trust that app! [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, Daily News, News, Technology

4.81.1K Ratings

🗓️ 6 September 2025

⏱️ 22 minutes

🧾️ Download transcript

Summary

Today we are joined by Selena Larson, co-host of Only Malware in the Building and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at Proofpoint, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft’s upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:10.1

At TALIS, they know cybersecurity can be tough and you can't protect everything,

0:17.6

but with TALIS, you can secure what matters most.

0:23.2

With TALIS's industry-leading platforms, you can protect critical applications, data, and identities, anywhere and at scale with the highest

0:29.7

ROI. That's why the most trusted brands and largest banks, retailers, and healthcare companies in the

0:36.1

world rely on Talis to protect what matters most. Applications, retailers, and healthcare companies in the world rely on Talis to protect what matters most.

0:40.0

Applications, data, and identity.

0:42.6

That's Talis.

0:44.0

T-H-A-L-E-S.

0:45.8

Learn more at Talisgroup.com slash cyber.

0:50.0

Thank you. Hello, everyone, and welcome to the Cyberwires Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts

1:11.5

tracking down the threats and vulnerabilities, solving some of the hard problems and protecting

1:16.6

ourselves in a rapidly evolving cyberspace. Thanks for joining us.

1:26.6

In this particular campaign, it was pretty interesting because the threat actors will impersonate various fake Microsoft Oath applications and ultimately lead to credential theft.

1:38.7

That's Selena Larson, staff threat researcher and lead for intelligence analysis and strategy at ProofPoint.

1:45.8

The research we're discussing today is titled Microsoft OOath App Impersonation Campaign leads to MFAFishing.

2:00.2

So sometimes we see Microsoft Oath app impersonation trying to gain access via the malicious app, various permissions and stuff.

2:09.6

But in this case, it was used more as a vehicle to enable the credential fishing, which was pretty interesting.

2:14.6

Well, let's back up just a step.

2:16.8

Can you describe for us what exactly we're

2:19.0

talking about when we say MFA fishing? Of course. So MFA fishing is multifactor authentication fishing.

2:25.9

So typically, historically, people will have a username and password to log into things.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.