Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and enabling account takeover.
We haven't written up this one. HackerNoon has the full story — the link below goes straight to it.