Follow the latest coverage, related explainers and connected technology stories.
Researchers found that the BigBear 2.0 phishing-as-a-service framework was used to hijack Microsoft 365 sessions after victims completed multi-factor authentication, and to steal thousands of credentials and cookies.