It's been a bit quiet on the news front over the last 24 hours, but we've still got a couple of interesting updates for you, including a new phishing technique and a push for tech companies to tackle phone theft. Let's dive in:
CoPhish - New OAuth Phishing via Microsoft Copilot 🎣
- Datadog Security Labs has unveiled 'CoPhish', a novel OAuth phishing technique that weaponises Microsoft Copilot Studio agents.
- This method exploits the ability to host malicious chatbots on legitimate Microsoft domains (copilotstudio.microsoft.com), making fraudulent OAuth consent requests appear highly credible to users.
- Attackers can target application administrators to grant permissions to malicious apps, enabling session token exfiltration without user awareness. Microsoft is working on fixes, but organisations should review consent policies and monitor Copilot Studio agent creation events.
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/security/new-cophish-technique-wraps-oauth-phishing-in-microsoft-copilot/
UK MPs Demand Tech Action on Phone Theft 📱
- UK Members of Parliament are urging the Home Secretary to mandate stronger technical measures from smartphone manufacturers (Apple, Google, Samsung) to combat rising phone theft.
- Metropolitan Police data shows 117,211 phones stolen in 2024, a 25% increase since 2019, with only a 1% charge/conviction rate. Around 75% of these devices are resold internationally.
- The committee advocates for cloud-based blocking or IMEI-linked device locks to render stolen handsets useless for resale, thereby reducing demand in criminal markets.
🕵🏼 The Register | https://go.theregister.com/feed/www.theregister.com/2025/10/25/uk_committee_phone_theft/
#CyberSecurity #ThreatIntelligence #Phishing #OAuth #MicrosoftCopilot #InfoSec #UKGov #PhoneTheft #CyberCrime #SecurityNews