O-UNC-066 uses voice phishing combined with deceptively authentic phishing websites and manually controlled PHP panels to steal access from Microsoft 365 customers.
Passwords remain widespread in enterprises because they are familiar, not because they are secure — security teams are therefore migrating to identity-based authentication.
Microsoft is ending support for SMS and voice authentication in Entra ID from February 2027, forcing enterprises to switch to passkeys as the only remaining native MFA method.
Microsoft enforces migration from SMS/voice MFA to Passkeys in Entra ID with hard block starting February 1, 2027, shifting costs to paid third-party providers for organizations with compliance requirements.
The breakthrough of the EUDI Wallet depends on implementing phishing-resistant authentication, adaptive security, and secure integration with existing IAM systems.
Google introduces biometric camera authentication in reCAPTCHA that analyzes hand gestures, but has already been bypassed through AI-generated animations.
New phishing campaigns exploit genuine Microsoft authentication dialogs to manipulate users into granting access authorization, bypassing password theft and multi-factor authentication.
ATG systems at gas stations and industrial facilities are threatened by authentication vulnerabilities and injection attacks, requiring immediate measures for isolation and hardening.