Researchers in cybersecurity are alerting the public to a new campaign of QR code phishing, often known as quishing, which uses Microsoft Sway infrastructure to host phony websites. This underscores the misuse of trustworthy cloud services for malevolent intent.
According to Jan Michael Alcantara, a researcher at Netskope Threat Labs, an attacker can help victims accept the content by employing genuine cloud applications, which give them legitimacy.
A victim can also be convinced of the legitimacy of a Sway page by using their Microsoft 365 account, into which they are already logged in. Additionally, Sway can be shared via an iframe installed read more about New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
