
Cybersecurity
Phishing Service Bypasses Microsoft 365 MFA
A new phishing-as-a-service platform called EvilTokens has compromised over 340 Microsoft 365 organizations. The attack tricks users into authorizing a malicious app via a device login flow, effectively bypassing multi-factor authentication and granting attackers access to their accounts without needing passwords or MFA codes.
The Hacker News1 min read