[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxF8WFZkWoCN1wa8d2mSVP506sgu1fmyfyUSn62Jee7s":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"ca6b7905-e190-4bdd-bc9e-fc79ce4fca41","aitm-phishing-service-bypasses-mfa-at-hundreds-of-organizations","6a5bb116-8af0-44eb-a92e-c529f9f104cc","AiTM Phishing Service Bypasses MFA at Hundreds of Organizations","BigBear 2.0 exploits an adversary-in-the-middle (AiTM) technique using Evilginx2 to sit between users and Microsoft 365, intercepting session cookies after MFA is completed — effectively rendering standard MFA useless. This attack demonstrates that MFA alone is not a silver bullet; session hijacking bypasses the authentication layer entirely without ever needing the user's password or OTP again. The use of geo-matched residential proxies and JavaScript-based FIDO2 interference makes detection significantly harder for both users and security teams. This matters because over 5,000 credential sets were stolen across 258 organizations, exposing sensitive corporate data, email, and downstream systems to full account takeover.","**Immediate actions:**\n- Replace SMS\u002FTOTP-based MFA with phishing-resistant FIDO2 hardware security keys (e.g., YubiKey) that bind authentication to the legitimate origin domain.\n- Enable Microsoft Conditional Access policies to enforce token binding and restrict session reuse from unexpected geolocations or new devices.\n- Audit all Microsoft 365 accounts for suspicious active sessions and revoke anomalous tokens immediately.\n\n**Long-term improvements:**\n- Adopt a Zero Trust architecture that continuously validates session context (device health, IP reputation, behavior) beyond the initial authentication event.\n- Implement Microsoft Entra ID's Continuous Access Evaluation (CAE) to invalidate tokens in near-real-time when risk signals are detected.\n- Train users to recognize credential-harvesting proxy pages, emphasizing that the URL bar and certificate details must always be verified before entering credentials.\n\n**Detection measures:**\n- Deploy SIEM rules to alert on impossible travel, simultaneous sessions from disparate IPs, and residential proxy IP ranges associated with known phishing infrastructure.\n- Enable Microsoft 365 Unified Audit Logging and forward logs to a SIEM to detect anomalous OAuth token grants and unexpected mail-forwarding rule creation post-compromise.\n- Integrate threat intelligence feeds for known AiTM\u002FEvilginx infrastructure to proactively block phishing domains at the DNS and email gateway level.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 6: Access Control Management","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-63B: Digital Identity Guidelines — Phishing-Resistant AAL3 Authenticators","NIST AC-17: Remote Access","NIST SI-4: Information System Monitoring","NIST IA-5: Authenticator Management","MITRE ATT&CK T1557: Adversary-in-the-Middle","MITRE ATT&CK T1539: Steal Web Session Cookie","GDPR Article 32: Security of Processing","NIST Zero Trust Architecture (SP 800-207)","published","2026-09-07T16:20:25.714962+00:00","2026-09-07T16:20:25.374+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fbigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations\u002F","bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations-71696e","BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]