1 story taggedadversary-in-the-middle.
A rented phishing service quietly harvested Microsoft 365 credentials and two-factor codes across US and European companies for nearly two years.