Threat researchers report that China-aligned TA419 targeted U.S. AI policy experts using reply-triggered adversary-in-the-middle phishing designed to capture Microsoft credentials and session cookies. Defenders should review identity-provider sign-in activity, enforce phishing-resistant MFA where possible, and investigate suspicious consent, session, and inbox-rule changes.

Source: The Hacker News

This report is based on the cited source. Organizations should consult vendor guidance and their own telemetry before acting.

By Allan