DJBSEC's CyberNews 2026-08-27
Today’s daily news covers the following categories: Phishing
Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions Across 3,500 Organizations
Phishing
A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks against 3,518 organizations and the potential compromise of more than 4,500 Microsoft 365 accounts. The kit uses adversary-in-the-middle phishing pages to relay usernames, passwords, and MFA codes to Microsoft in real time, then steals the authenticated session cookie returned after a successful login. Researchers recorded 9,332 compromise events across 94 countries, with U.S. organizations accounting for nearly 64 percent of identified victims and technology, manufacturing, and education among the most targeted sectors. Because attackers obtain valid session cookies, simply resetting a victim’s password may not remove their access, allowing them to continue using Microsoft 365 and connected SSO applications. Defenders should prioritize phishing-resistant authentication such as FIDO2 or passkeys and, after suspected compromise, revoke active sessions and tokens while reviewing mail-forwarding rules, OAuth grants, and activity associated with the stolen identity.
Enjoy Reading This Article?
Here are some more articles you might like to read next: