Cybersecurity News
Filters
Filtered by tag: microsoft 365 × Clear
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
Matched: health
A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.
Microsoft Teams Outage Largely Mitigated After Users Lost Access to Multiple Features
Matched: health
Microsoft Teams suffered an outage on August 26, 2026, primarily affecting Asia-Pacific users who could not join or create meetings, with some unable to share screens. Microsoft attributed the disruption to maintenance activity with unintended consequences. By 7:26 a.m. IST, the company reported the issue largely mitigated and said engineers would monitor for 15–30 minutes to prevent recurrence. One-to-one calls remained functional during the incident.
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Huntress researchers found that Conditional Access misconfigurations left 55 organizations vulnerable despite having MFA enabled. Two real attack cases bypassed policies that appeared properly set up, exposing gaps invisible to standard reviews. Huntress's Managed Identity Security Posture Management tool is designed to detect these configuration flaws before attackers can exploit them.
