Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New VoidProxy Fishing Service Target Microsoft 365, Google Accounts
    Security

    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts

    PineapplesUpdateBy PineapplesUpdateSeptember 14, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts

    A newly discovered Fishing-e-Service (PHAAS) platform, named VoidProxy, targets Microsoft 365 and Google accounts, including third-party single sign-on-on-on-on-on-on-on-on-on-on-on.

    The platform uses a real-time credentials, multi-factor authentication (MFA) code, and adverse-in-media (AITM) strategy to steal the session cookies.

    Was discovered by voidproxy Okta Thret Intelligence Researchers, who describe it as scalable, awaic and sophisticated.

    The attack begins with emails from an agreement made in email service providers, such as continuous contact, active campaign, and informed, which contain small links in whicch that sends recipients to the recipients after several redirects.

    Malivedy sites are hosted on the disposable low -cost domains.

    Visitors are first challenged a cloudflair captcha to filter the bots and increase the spirit of validity, while a cloudflair worker environment is used to filter traffic and load pages.

    Cloudflare captcha step on malicious site
    Cloudflare captcha step on malicious site
    Source: octa

    The selected goals modify a page that mimics a microsoft or Google login, while the rest are funnels on the “reception” page that offers no danger.

    If credentials are typed into a fishing form, the requests are estimated through the adverse-in-in-media (AITM) of VoidProxy for the request google or microsoft server.

    Fishing page is served by voidproxy
    Fishing page is served by voidproxy
    Source: octa

    Federed accounts, like those using Okta for SSO, are redirected to a second-step fishing page, which flows with Okta with Microsoft 365 or Google SSO. These requests were taken out for the OkTT server.

    The proxy server of the service performs traffic between the victim and legitimate service when capturing the user name, password and MFA code into transit.

    When the valid service issues a session cookie, VoidProxy intercepts him and creates a copy that is made available to the attackers on the administrator panel of the platform.

    Voidproxy administrator panel
    Voidproxy administrator panel
    Source: octa

    Octa mentioned that users who enrolled in fishing-resistant authentication such as Okta Fastpass were protected from the flow of VoidProxy attack and received a warning about their account attack.

    The recommendations of the researchers include restricting the access of sensitive apps to only managed equipment, implementing risk-based access control, using IP sessions for administrative apps and forcing them to re-certification to try sensitive tasks.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    accounts Fishing Google Microsoft service target VoidProxy
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleVibe coding has converted senior gods to ‘AI Babyitors’, but they say it is worth it.
    Next Article AI, Karen Hao on the Empire of AGI EGILists and the cost of faith
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How a simple link allowed hackers to bypass Copilot’s security guardrails – and what Microsoft did about it

    January 19, 2026
    Startups

    OpenAI, Anthropic and Google all have new AI healthcare tools – here’s how they work

    January 17, 2026
    Startups

    Why I recommend this budget Motorola phone over cheaper options from Samsung and Google

    January 13, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    This browser is designed for those who never close tabs

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.