# Forg365 PhaaS Targets Microsoft 365 via Device Code and AitM Session Theft

A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users by abusing the device code authentication flow and performing adversary-in-the-middle session theft. This technique bypasses multi-factor authentication and steals session tokens, enabling persistent access to accounts. The emergence of such a tool heightens risks for organizations reliant on Microsoft 365, requiring enhanced monitoring and user training.

**Importance:** 3/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html) — Mon, 13 Jul 2026 18:33:33 +0530