A new phishing attack platform endangers Microsoft environments.

OAuth consent is the phishing vector MFA misses—long-lived tokens and cross-app access bypass trusted identity controls.

A new phishing attack platform endangers Microsoft environments.

MFA? No problem, says crimeware that tricks users into handing attackers the keys to M365