{
  "id": 28654,
  "title": "Computer Security: One click to many",
  "url": "https://urgent.news/2026/07/28/computer-security-one-click-to-many",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-07-28T10:25:10.000Z",
  "source": {
    "name": "CERN",
    "slug": "cern",
    "url": "https://home.cern/computer-security-one-click-to-many/"
  },
  "original_language": "en",
  "account": "In a recent security breach at CERN, a seemingly harmless email led to a chain reaction of compromised accounts and unauthorized access. The email, which appeared to be routine, requested users to click on a link to a Word document. Unbeknownst to many recipients, this link directed them to a non-CERN domain, setting the stage for a malicious attack.\n\nThe attack leveraged Microsoft's cloud configuration, specifically a feature known as \"device code authentication.\" This feature, designed for user convenience by allowing prolonged access without daily logins, inadvertently made it easier for attackers to exploit. By copying a \"verification code\" displayed on a landing page, a victim unwittingly granted unauthorized access to their account. This breach not only jeopardized the individual's account but also opened the door for further attacks.\n\nOnce inside the victim's mailbox, an AI-enabled automation system scanned for additional email addresses, creating a cascade of attacks. The system identified over 5000 potential targets within CERN, sending them tailored emails with plausible hooks such as \"Back orders\" or \"Q'2 EMEA Project.\" Of these, 108 recipients fell for the ruse, thereby compromising their Microsoft cloud tokens. These victims had to undergo a cumbersome process of re-authenticating via CERN's 2FA-protected Single Sign-On system.\n\nDespite ongoing investigations by CERN's Computer Security Office into measures to prevent such attacks, like revoking device code authentication or reducing its validity period, the organization emphasized the importance of vigilance. They urged all staff and users to scrutinize every email, hovering over URLs and links to verify their legitimacy. Should a link seem suspicious, they advised against clicking, especially if the destination is unknown or unexpected, as was the case with the \"mata-asia[.]com\" domain.\n\nCERN's Computer Security Office encourages the community to stay informed about security incidents and issues. They invite anyone interested to follow their Monthly Report or visit the official website for further information or assistance. For any queries or help, they can be reached at Computer.Security@cern.ch.",
  "summary": "More senior colleagues might still recall the regular “clicking” campaigns that were intended to raise security awareness within the Organization among staff and users. With the roll-out of two-factor authentication, such campaigns were dropped. However, the world continues to turn and novel functionality and novel attack vectors try to circumvent our protections. And they have […]",
  "key_points": [
    "Seemingly harmless email led to compromised accounts at CERN.",
    "Attack exploited Microsoft's device code authentication feature.",
    "108 recipients fell for phishing emails, compromising Microsoft cloud tokens."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}