Forg365 PhaaS Targets Microsoft 365 via Device Code and AitM Session Theft
A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users by abusing the device code authentication flow and performing adversary-in-the-middle session theft. This technique bypasses multi-factor authentication and steals session tokens, enabling persistent access to accounts. The emergence of such a tool heightens risks for organizations reliant on Microsoft 365, requiring enhanced monitoring and user training.