Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Ranch at Rock Creek’s brilliant 5-star business strategy

    December 4, 2025

    Your favorite AI tool just barely missed this security review – why that’s a problem

    December 4, 2025

    I saw drone delivery launch in Atlanta – how they work and which cities are next

    December 4, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New VoidProxy Fishing Service Target Microsoft 365, Google Accounts
    Security

    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts

    PineapplesUpdateBy PineapplesUpdateSeptember 14, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New VoidProxy Fishing Service Target Microsoft 365, Google Accounts

    A newly discovered Fishing-e-Service (PHAAS) platform, named VoidProxy, targets Microsoft 365 and Google accounts, including third-party single sign-on-on-on-on-on-on-on-on-on-on-on.

    The platform uses a real-time credentials, multi-factor authentication (MFA) code, and adverse-in-media (AITM) strategy to steal the session cookies.

    Was discovered by voidproxy Okta Thret Intelligence Researchers, who describe it as scalable, awaic and sophisticated.

    The attack begins with emails from an agreement made in email service providers, such as continuous contact, active campaign, and informed, which contain small links in whicch that sends recipients to the recipients after several redirects.

    Malivedy sites are hosted on the disposable low -cost domains.

    Visitors are first challenged a cloudflair captcha to filter the bots and increase the spirit of validity, while a cloudflair worker environment is used to filter traffic and load pages.

    Cloudflare captcha step on malicious site
    Cloudflare captcha step on malicious site
    Source: octa

    The selected goals modify a page that mimics a microsoft or Google login, while the rest are funnels on the “reception” page that offers no danger.

    If credentials are typed into a fishing form, the requests are estimated through the adverse-in-in-media (AITM) of VoidProxy for the request google or microsoft server.

    Fishing page is served by voidproxy
    Fishing page is served by voidproxy
    Source: octa

    Federed accounts, like those using Okta for SSO, are redirected to a second-step fishing page, which flows with Okta with Microsoft 365 or Google SSO. These requests were taken out for the OkTT server.

    The proxy server of the service performs traffic between the victim and legitimate service when capturing the user name, password and MFA code into transit.

    When the valid service issues a session cookie, VoidProxy intercepts him and creates a copy that is made available to the attackers on the administrator panel of the platform.

    Voidproxy administrator panel
    Voidproxy administrator panel
    Source: octa

    Octa mentioned that users who enrolled in fishing-resistant authentication such as Okta Fastpass were protected from the flow of VoidProxy attack and received a warning about their account attack.

    The recommendations of the researchers include restricting the access of sensitive apps to only managed equipment, implementing risk-based access control, using IP sessions for administrative apps and forcing them to re-certification to try sensitive tasks.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    accounts Fishing Google Microsoft service target VoidProxy
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleVibe coding has converted senior gods to ‘AI Babyitors’, but they say it is worth it.
    Next Article AI, Karen Hao on the Empire of AGI EGILists and the cost of faith
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Dells put $6.25 billion into children’s ‘Trump accounts’

    December 3, 2025
    Startups

    Here’s how much Apple, Meta, Google and more employees make

    December 2, 2025
    Startups

    The Google Pixel Watch 4 is my favorite smartwatch — and it’s on sale for its lowest price ever

    November 26, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    The Ranch at Rock Creek’s brilliant 5-star business strategy

    December 4, 2025

    Your favorite AI tool just barely missed this security review – why that’s a problem

    December 4, 2025

    I saw drone delivery launch in Atlanta – how they work and which cities are next

    December 4, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.