MFA is (Unconditionally) Not Enough

MFA is (Unconditionally) Not Enough Microsoft has seen a trending number of instances whereby an Office 365 user is phished and has their O365 session hijacked. The adversary uses the victim’s token to sidestep Multifactor Authentication (MFA), allowing the attacker into the victim’s email where they can impersonate and ask for bogus wire transfers. This […]