Feed›Social Engineering›New phishing kits target Microsoft 365 accounts, evade MFA...
Social EngineeringBleeping Computer
8.5 — CRITICAL

New phishing kits target Microsoft 365 accounts, evade MFA

📅 14 July 2026 at 12:49 UTC📰 Bleeping ComputerView original source ↗
New phishing kits target Microsoft 365 accounts, evade MFA

Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Two new phishing kits, Jalisco and OmegaLord, target Microsoft 365 accounts using techniques that defeat multi-factor authentication (MFA), exploiting OAuth 2.0 Device Authorization Grant flow and social engineering tactics.

⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
device-code phishingPDF reader phishing
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Microsoft 365 accounts
🛡️Recommended Actions
1Reduce Entra ID device-registration limit to one or two
2Block device code authentication through Microsoft Entra Conditional Access
3Restrict the OAuth Device Authorization grant in Okta
📦Affected Products
Microsoft 365

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed