Insights from the front lines of cyber
defense powered by Eye Research.

Microsoft login page abused as phishing redirector

Eye Security has observed threat actors using links to login.microsoftonline.com in phishing emails. These are not device code phishing or consent phishing attempts. Rather, the threat actors are using the legitimate login page to redirect to a malicious phishing page.

How we Rooted Copilot

Read how we explored the Python sandbox in Copilot and got root on the underlying container

STORIES FROM THE SOC: Eye see you, Axios

Eye Security investigates new threat actors and their methods, focusing on business email compromise (BEC). For example, an alert was triggered when a phishing attempt bypassed multi-factor authentication. Analysts quickly revoked access, limiting damage to a stolen password. Their rapid response ensures threats are mitigated effectively.