Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA

BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA

Posted on September 8, 2026 By CWS

In a significant cybersecurity development, the BigBear 2.0 phishing operation is utilizing advanced techniques to breach Microsoft 365 accounts. This campaign effectively bypasses multi-factor authentication (MFA) by capturing session cookies, posing a serious threat to digital security.

How BigBear 2.0 Operates

BigBear 2.0 is an iteration of the Evilginx2 framework, specifically rebranded to target Microsoft 365 users. By sending deceptive sign-in links via email, the campaign reroutes victims to a counterfeit Microsoft sign-in page. Here, it intercepts the user’s credentials and session data while simultaneously redirecting their traffic to the legitimate service.

The operation, uncovered by CloudSEK analysts in June 2026, involves a network of 42 virtual private server nodes. Researchers connected the campaign to an individual known as General Boss, uncovering over 5,137 compromised records from various organizations and individuals across more than 40 countries.

Technical Exploits and Impact

The phishing scheme employs an adversary-in-the-middle approach, capturing session cookies post-authentication. These cookies allow attackers to impersonate users across Microsoft services such as Teams, SharePoint, and OneDrive without needing their passwords again. By leveraging residential proxies, the operation evades detection and circumvents security key authentication.

With 474 complete session captures and thousands of session cookies and passwords exposed, the implications for IT services and managed service providers are particularly concerning. A single compromised provider could potentially grant attackers access to numerous client environments.

Mitigation Strategies and Future Outlook

Organizations must approach stolen cookies as identity threats rather than simple password issues. Immediate actions include password resets, session revocation, and monitoring for unauthorized access. Employing phishing-resistant authentication methods, such as FIDO2 or WebAuthn, can significantly mitigate risks.

As phishing tactics evolve, maintaining vigilant security protocols is crucial. Monitoring unusual IP activity and implementing robust email filtering can help detect and prevent such threats. Continuous adaptation to emerging cyber threats will be essential for maintaining operational security.

Users should remain cautious of unexpected sign-in prompts and verify their authenticity through known channels rather than email links. BigBear 2.0 highlights the necessity of combining MFA with advanced security practices to safeguard sensitive data and maintain trust in digital communications.

Cyber Security News Tags:BigBear 2.0, CloudSEK, cookie theft, Cybersecurity, Evilginx2, identity theft, IT security, MFA, Microsoft 365, Phishing, session hijacking

Post navigation

Previous Post: Crypto Fraudsters Face Justice After $240M Bitcoin Heist
Next Post: Chainguard Reaches 1 Billion Build Manifests Milestone

Related Posts

239 Malicious Android Apps on Google Play With Downloaded Over 40 Million Times 239 Malicious Android Apps on Google Play With Downloaded Over 40 Million Times Cyber Security News
Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web Cyber Security News
DDoS Attacks Surge: Link11’s 2026 Cyber Report Insights DDoS Attacks Surge: Link11’s 2026 Cyber Report Insights Cyber Security News
Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks Cyber Security News
Massive Spike in Password Attacks Targeting Cisco ASA VPN Followed by Microsoft 365 Massive Spike in Password Attacks Targeting Cisco ASA VPN Followed by Microsoft 365 Cyber Security News
PoisonSeed Phishing Kit Bypasses MFA to Acquire Credentials from Individuals and Organizations PoisonSeed Phishing Kit Bypasses MFA to Acquire Credentials from Individuals and Organizations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Reflectiz Unveils Advanced Website Penetration Testing
  • SAP Addresses Critical Vulnerability in Passport Processing
  • Chainguard Reaches 1 Billion Build Manifests Milestone
  • BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA
  • Crypto Fraudsters Face Justice After $240M Bitcoin Heist

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Reflectiz Unveils Advanced Website Penetration Testing
  • SAP Addresses Critical Vulnerability in Passport Processing
  • Chainguard Reaches 1 Billion Build Manifests Milestone
  • BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA
  • Crypto Fraudsters Face Justice After $240M Bitcoin Heist

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark