news.mlab.sh
Back to the feed
threat-intel

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

High
Image: The Hacker News
Summary

The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authentication. Attackers are leveraging stolen sessions to gain access to corporate email, trusted business accounts, and other sensitive data, often bypassing existing MFA protections. The campaign highlights a significant evolution in phishing tactics and necessitates a shift towards proactive measures like session theft incident response and enhanced authentication.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.