Mitiga at RSAC 2025: Visit our booth, attend our speaking sessions, and schedule a meeting with us!

August 25, 2022

CEOs beware: senior executives targeted in complex Office 365 attack

Researchers discovered the complicated attack that involved phishing, a flaw in Office 365 and adversary-in-the-middle exploits.

August 25, 2022

Crooks target top execs on Office 365 with MFA-bypass scheme

'Widespread' campaign hunts for multimillion-dollar transactions: A business email compromise scheme targeting CEOs and CFOs using Microsoft Office 365 combines phishing with a man-in-the-middle attack to defeat multi-factor authentication.

August 25, 2022

Mitiga: Attackers evade Microsoft MFA to lurk inside M365

During an incident response investigation, Mitiga discovered attackers were able to create a second authenticator with no multifactor authentication requirements.

August 25, 2022

5 Tips To Help You Prepare for a Potential Slack or Office 365 Breach

Over the last two years, digital transformation projects have accelerated and cloud-based collaboration platforms, such as Office 365 and Slack, have been adopted even more rapidly (no doubt accelerated by the pandemic and increased accessibility via smart phones and reliable internet access).

August 25, 2022

Microsoft 365 accounts are being targeted by new email scams

Cybersecurity experts are warning of a new, widespread business email compromise (BEC) campaign, which seeks to reroute large money transactions to bank accounts belonging to the attackers.

August 25, 2022

Microsoft 365 business users targeted with new DocuSign phishing scam

A new business email compromise (BEC) campaign has been targeting Microsoft 365 organizations in a bid to hack corporate executives’ accounts and maliciously divert business payments.

August 25, 2022

Hackers are attempting to steal millions of dollars from businesses by bypassing multi-factor authentication

Cybersecurity researchers detail a BEC scam targeting high-level Microsoft Office 365 accounts, even if they're protected with MFA.

August 24, 2022

Advanced business email compromise campaign targeting Microsoft 365 organizations

Researchers spotted a sophisticated business email compromise (BEC) campaign targeting Microsoft 365 organizations, leveraging inherent weaknesses in Microsoft 365 Multi-Factor Authentication (MFA), Microsoft Authenticator, and Microsoft 365 Identity Protection.

August 24, 2022

How attackers use and abuse Microsoft MFA

Microsoft has been pushing for the use of multi-factor authentication (MFA) to thwart attackers for many years. But threat actors are keeping up with the increasing enterprise adoption of MFA and are constantly coming up with ways to bypass the additional protection it offers.