Healthcare Cybersecurity News

Filtered by category: Cybersecurity News, tag: phishing × Clear

Cybersecurity News

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Matched: health

A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.

Cybersecurity News

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Matched: health

Scammers are running fake Microsoft-branded security scan websites that display fabricated system warnings and artificially low security scores to frighten visitors. The sites instruct users to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. During that call, operators request remote access to complete a fake refund, giving criminals direct control of the device. Malwarebytes identified 11 related sites sharing one server.