MFA? No problem, says crimeware that tricks users into handing attackers the keys to M365 The FBI has issued a public service announcement warning about a new phishing kit that stealing Microsoft OAuth tokens at an alarming rate. OAuth token theft is a serious headache for organizations because stolen tokens can bypass multi factor authentication MFA and grant access to privileged accounts within an organization without needing to know their credentials. Think corporate espionage, data theft,...