A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session. Threat researchers at ANY.RUN discovered that the Adversary-in-the-Middle (AiTM) framework generated thousands of potential compromise events from late 2024 through 2026, […]
Read the original article: