A new phishing method has emerged that can trick employees into bypassing Microsoft 365’s multi-factor authentication (MFA). This attack uses a clever tactic involving OAuth device registration to give hackers ongoing access to a victim’s account without needing their password. It’s a sophisticated way to break into Microsoft accounts, and it’s mostly targeting businesses and










