CloudSEK reports BigBear 2.0, an Evilginx2-based PhaaS, compromised Microsoft 365 accounts at 258 organizations and stole 5,000+ records. It proxies logins to capture passwords, MFA data and session cookies for replay, bypassing standard MFA. Enforce phishing-resistant auth and token theft detection. #Microsoft365 #Phishing #MfaBypass
https://cyberworldops.eu/en/bigbear-20-phishing-service-hijacked-microsoft-365-sessions-at-258
About This Hashtag
#mfabypass
3 posts
Last used 11d
#mfabypass
3 posts· Last used 11d
CERT/CC discloses six Logto vulnerabilities, including CVE-2026-15611 and CVE-2026-15616, that enable SSO authentication bypass and MFA skipping.
#Logto #SSO #SAML #OIDC #MFABypass #CERTCC
https://securityonline.info/logto-vulnerabilities-sso-bypass/?utm_source=mastodon&utm_medium=jetpack_social
A misconfigured server exposed three AiTM phishing operators running Evilginx MFA bypass and Device Code attacks on Microsoft 365 accounts.
#AiTMPhishing #Evilginx #MFABypass #Microsoft365 #Phishing
https://securityonline.info/aitm-phishing-operators-exposed/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts