Social EngineeringBleeping Computer
8.5 — CRITICAL
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Two new phishing kits, Jalisco and OmegaLord, target Microsoft 365 accounts using techniques that defeat multi-factor authentication (MFA), exploiting OAuth 2.0 Device Authorization Grant flow and social engineering tactics.
⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
device-code phishingPDF reader phishing
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Microsoft 365 accounts
🛡️Recommended Actions
1Reduce Entra ID device-registration limit to one or two
2Block device code authentication through Microsoft Entra Conditional Access
3Restrict the OAuth Device Authorization grant in Okta
📦Affected Products
Microsoft 365
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
