New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password

A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight […]

This article has been indexed from IT Security Guru

Read the original article: