
BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions to Bypass MFA
First identified in June 2026, the operation targeted Microsoft 365 users and was reportedly still active during the investigation. Researchers gained administrative access to the campaign’s management panel and found it had controlled 42 virtual private server nodes during its lifecycle. Most of the servers were hosted by Vultr, operated by The Constant Company LLC. […]
The post BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions to Bypass MFA appeared first on Cyber Security News.