Kryptovalutaticker:
sysadmin från Cyber Security News

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Guru Baran
14 hours ago
5 Visningar
0 Kommentarer
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session hijacking, OAuth device-code abuse, and real-time reverse-proxy credential relay, but all three converge on the same outcome: a fully authenticated M365 session or token in the attacker’s hands without ever “cracking” MFA itself. For defenders, this represents a critical shift in the threat landscape. Traditional advice to “enable...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!