GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a newly identified phishing kit that turns a normal Microsoft 365 sign-in into an account takeover. It does not need to steal a password. Instead, it persuades people to approve a login that gives criminals access to their work account. The campaign began with ordinary-looking messages submitted through business contact forms. Attackers posed […]

This article has been indexed from Cyber Security News

Read the original article: