Microsoft Warning This Phishing Attack Can Skip Your Defenses And Has Hit 10 000 Firms Already
AiTM sounds like bad news as the phishing sites can skip authentication on sites even when the user has enabled multi-factor authentication (MFA). The attack involves hijacking a user’s sign-in session, and using stolen credentials and session cookies to access victims’ email for business email compromise (BEC) fraud. MFA is one of the key ways organizations can protect themselves from phishing and credential theft attacks. The Biden administration made MFA mandatory for federal agencies while other organizations, such as the Python Software Foundation, are making MFA a minimum requirement for critical projects....