6
submitted 5 months ago* (last edited 5 months ago) by RegularJoe@lemmy.world to c/microsoft@lemmy.world
top 3 comments
sorted by: hot top controversial new old
[-] SGforce@lemmy.ca 1 points 5 months ago

This requires all authentication codes to be sent to the attacker in the first place. Why wouldn't they just put the code in themselves at that point?

[-] oantby@lemmy.today 1 points 5 months ago

They don’t have an authentication code; just an identification code. You log in elsewhere and put in the code so Microsoft knows which device you actually want to log in on. Think e.g. logging into most streaming services on a Smart TV - get the code and take it to your phone, where you actually log in.

[-] slazer2au@lemmy.world 1 points 5 months ago

How is this new? Evilginx has been around for years.

this post was submitted on 01 Mar 2026
6 points (100.0% liked)

Microsoft

960 readers
1 users here now

founded 3 years ago
MODERATORS