1mo ago · bleeping-computer
Two new phishing kits, Jalisco and OmegaLord, are targeting Microsoft 365 accounts using techniques that bypass multi-factor authentication (MFA). Jalisco leverages device-code phishing via OAuth 2.0 Device Authorization Grant, tricking users into authorizing attacker-controlled devices. OmegaLord uses a fake PDF reader login page to harvest credentials and phone numbers, aiding in MFA bypass. Both kits enable rapid data exfiltration from SaaS platforms like SharePoint, often within minutes of compromise.