generalnews.media
importance 3/5 Exclusive

Forg365 PhaaS Targets Microsoft 365 via Device Code and AitM Session Theft

A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users by abusing the device code authentication flow and performing adversary-in-the-middle session theft. This technique bypasses multi-factor authentication and steals session tokens, enabling persistent access to accounts. The emergence of such a tool heightens risks for organizations reliant on Microsoft 365, requiring enhanced monitoring and user training.

Security

Sources (1)

security
← Back to home