Researchers identified BigBear 2.0, an Evilginx2-based platform that bypasses multi-factor authentication by suppressing FIDO2 prompts and using residential proxies. The operation intercepted credentials across 258 organizations, compromising over 5,000 records. This threat highlights vulnerabilities in Microsoft 365 environments where attackers can steal session cookies and passwords despite security controls.
Relevant URL: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/