CyberHighSingle-sourceDeveloping
7.0
Threat actors shift to multi-agent AI frameworks for automated credential theft
BleepingComputer·about 12 hours ago
A phishing-as-a-service framework, BigBear 2.0, has successfully bypassed multi-factor authentication at 258 organizations, compromising over 5,000 Microsoft 365 accounts. The attack leverages adversary-in-the-middle techniques to intercept session tokens, undermining MFA protections. This highlights a growing trend of credential theft despite MFA deployment, posing significant risk to enterprise security.