Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Microsoft 365 corporate users
Incident: Exposure of three active AiTM phishing operations via a misconfigured web server.
Impact: Unauthorized access to corporate mailboxes through MFA bypass and long-term session hijacking.
Attacker: codemado and mail-argenta
Analysis: Attackers are leveraging customized Evilginx forks to execute Adversary-in-the-Middle (AiTM) attacks that bypass standard MFA. By manipulating session cookie TTLs to last up to a year and abusing device-code flows, these actors maintain persistent access to corporate environments. The discovery highlights a dangerous trend where high-impact phishing frameworks are becoming easily accessible and highly modular.
Recommendations: Implement Conditional Access policies specifically to block device-code abuse.; Accelerate the rollout of FIDO2-compliant passkeys to neutralize proxy-based phishing.; Enforce Continuous Access Evaluation (CAE) to invalidate stolen session tokens more rapidly.
Source: The Hacker News / Lexfo
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source