Cyber Security News

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

PhishingCriticalphishing

Mirage2FA, a Phishing-as-a-Service platform, enables attackers to bypass Microsoft 365 MFA by allowing users to complete normal login, then stealing authenticated sessions via an adversary-in-the-middle attack. Thousands of compromise events have occurred since late 2024.

AI summary · generated with Claude

https://cybersecuritynews.com/microsoft-365-session-theft/