HackRead

New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA

PhishingHighphishing

Security researchers discovered the GhostCode phishing kit that exploits Microsoft OAuth to bypass MFA protections and steal credentials for Microsoft 365 accounts. The kit uses token-stealing techniques to gain unauthorized access despite multi-factor authentication being enabled, posing a significant threat to enterprise email security.

AI summary · generated with Claude

https://hackread.com/ghostcode-phishing-kit-hijack-microsoft-accounts-mfa/