Large-Scale Phishing Campaign Bypasses MFA

Hacks Web Security
Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.