CISO Intelligence
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
Source: BleepingComputer · Category: Threat Actor & Campaign Tycoon2FA phishing kit now supports device-code phishing and abuses Trustifi URLs to hijack Microsoft 365 accounts. Law firms depend on Microsoft 365; this is a direct threat to attorney and staff email accounts. Escalate to security team and user awareness program immediately. → Read