
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems […]
The post Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session appeared first on Cyber Security News.