Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Guru Baran
14 hours ago
3 Visninger
0 Kommentarer
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session hijacking, OAuth device-code abuse, and real-time reverse-proxy credential relay, but all three converge on the same outcome: a fully authenticated M365 session or token in the attacker’s hands without ever “cracking” MFA itself. For defenders, this represents a critical shift in the threat landscape. Traditional advice to “enable...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!