:

NEW PHISHING KITS BYPASS MICROSOFT 365 MFA

SECURITY DESK2 MIN READ
TUE, JUL 14, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Two newly discovered phishing kits, Jalisco and OmegaLord, are actively targeting Microsoft 365 accounts with techniques designed to circumvent multi-factor authentication protections.

Security researchers have identified two sophisticated phishing kits exploiting Microsoft 365 users despite MFA defenses. The kits, named Jalisco and OmegaLord, employ advanced techniques to steal credentials and authentication tokens, rendering traditional MFA protections ineffective. Both kits operate by creating convincing replicas of Microsoft 365 login pages. When users enter their credentials, the kits capture the information in real time. The critical difference from standard phishing attacks is their ability to intercept and relay MFA challenges, allowing attackers to complete authentication without the victim's knowledge. Jalisco uses a reverse-proxy approach, positioning itself between the user and Microsoft's servers. This method captures credentials and MFA tokens as they're transmitted, giving attackers legitimate session access. OmegaLord employs similar interception techniques with additional obfuscation to evade detection by security tools. These kits represent an escalation in phishing sophistication. Traditional MFA—typically SMS codes or authenticator apps—becomes ineffective when attackers control the authentication flow. Users who believe MFA protects them completely remain vulnerable to these attacks. Organizations using Microsoft 365 should implement additional security measures beyond standard MFA. Recommended protections include conditional access policies that flag unusual login locations or devices, passwordless authentication methods like Windows Hello or FIDO2 security keys, and user education about phishing risks. Microsoft 365 administrators should review login logs for suspicious activity and consider enforcing stricter authentication requirements for sensitive accounts. Security teams should monitor for phishing domains mimicking Microsoft properties and use threat intelligence to identify Jalisco and OmegaLord indicators of compromise. The discovery underscores a broader trend: as organizations adopt MFA, attackers develop more sophisticated methods to defeat it. Standard MFA alone is no longer sufficient for comprehensive account protection.

■ SOURCES

Bleeping ComputerHacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.

JUST NOWIndustry Desk

The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.

JUST NOWAI Desk

Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.

6H AGOIndustry Desk

A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.

6H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.