CISO Intelligence
CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
Source: Hackread · Category: Threat Actor & Campaign CalPhishing campaign exploits Outlook calendar invites and device code phishing to steal Microsoft 365 session tokens and bypass MFA. High relevance: law firm staff heavily dependent on M365; implement conditional access policies and disable device code auth where possible. → Read the full article