Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.

According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.

Mirage2FA Campaign

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Linux 7.3 improves performance when running out of vRAM

Linux 7.3 improves performance when running out of vRAM Source: Hacker News

Company Offering ‘100% Human-Written, Never AI’ Medical Research Is 100% AI

Company Offering ‘100% Human-Written, Never AI’ Medical Research Is 100% AI Source: Hacker News

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a