DJBSEC's CyberNews 2026-08-28

Today’s daily news covers the following categories: Phishing


Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions Across 3,500 Organizations

Phishing

A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks targeting 3,518 organizations and the potential compromise of 4,532 Microsoft 365 accounts. The kit uses adversary-in-the-middle phishing pages to relay usernames, passwords, and one-time MFA codes to Microsoft in real time, then captures the authenticated session cookie returned after a successful login. Researchers recorded 9,332 compromise events across 94 countries, with the United States accounting for nearly 64 percent of identified victims and technology, manufacturing, and education among the most affected industries. Because attackers obtain valid session cookies, simply resetting a victim’s password may not remove their access to Microsoft 365 and connected single sign-on applications. Defenders should prioritize phishing-resistant authentication such as FIDO2 or passkeys and treat suspected session theft as an identity compromise by revoking active sessions and tokens and reviewing mail-forwarding rules, OAuth grants, and account activity.

Read More




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24
  • DJBSEC's CyberNews 2026-08-21