Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Platform Greatness Bypasses MFA for Microsoft 365

Phishing Platform Greatness Bypasses MFA for Microsoft 365

Posted on August 5, 2026 By CWS

The Greatness phishing-as-a-service (PhaaS) platform has emerged as a significant threat to Microsoft 365 security, effectively bypassing multi-factor authentication (MFA). This platform captures legitimate sign-in tokens, allowing attackers unauthorized access to various cloud services as if they were the legitimate user.

Phishing Tactics and Campaigns

Recent campaigns have exploited fake RingCentral voicemail and performance-review emails to infiltrate inboxes. Despite failing SPF, DKIM, and DMARC checks, these emails bypassed security through domain-based safe-sender exclusions. Analysts at ZeroBEC discovered this activity during an investigation of phishing emails targeting a secured organization.

ZeroBEC’s report, shared with Cyber Security News, highlights the combination of real-time login relays, device-code phishing, and a centralized operator service delivered via Telegram. These tactics not only compromise individual mailboxes but also expose services like Outlook, Teams, and OneDrive, enabling further fraudulent activities.

Evolution of the Greatness Platform

Initially introduced as a phishing kit, Greatness has evolved into a comprehensive service offering pre-configured lures and tools targeting platforms such as Microsoft 365, iCloud, Yahoo, and Google Workspace. Attackers employ lookalike messages urging recipients to engage with purported recordings or appraisal notices.

The attack chain often begins with impersonation of a trusted brand, leading victims through redirects to attacker-controlled pages. This approach includes human verification steps, complicating routine scanning methods, and mimics tactics from recent MFA bypass campaigns.

Security Implications and Recommendations

Greatness’ ability to act as a live relay between victims and Microsoft 365 highlights a critical distinction in incident response. Simply resetting passwords may not be effective, as existing tokens remain valid. Security teams should revoke active sessions, scrutinize OAuth consents, and identify unfamiliar sign-ins that have passed MFA.

The platform also provides a device-code phishing route using document-themed pages. This alternative path is useful when a live proxy is not feasible. Despite infrastructure changes, core operational patterns remain consistent, necessitating vigilant monitoring.

Preventative Measures for Organizations

Organizations must audit safe-sender lists and transport-rule exclusions to prevent email protection failures due to configuration errors. Special treatment of domains should only occur when authentication checks are passed. Breach notices from vendors should prompt reviews of customer lists to mitigate potential spoofing risks.

Security teams can enhance detection by verifying sender, brand, and domain consistency. Investigating rapid access to multiple Microsoft 365 services from new networks and unusual MFA-approved logins can also indicate compromise. After suspected attacks, revoking tokens, rotating credentials, and inspecting mailbox rules are crucial steps.

In conclusion, the Greatness PhaaS platform underlines the need for robust security practices and continuous vigilance to prevent unauthorized access to cloud services, even with MFA in place.

Cyber Security News Tags:Authentication, cloud services, cyber attack, Cybersecurity, email security, Greatness, Malware, MFA, Microsoft 365, Phishing, security breach, Spoofing, token theft, ZeroBEC

Post navigation

Previous Post: Uppsala Security Joins Cyber Threat Alliance for Blockchain Insight
Next Post: Phishing-as-a-Service Kits Bypass MFA for M365 Breaches

Related Posts

Enhancing Alert Triage Efficiency for Tier 1 Teams Enhancing Alert Triage Efficiency for Tier 1 Teams Cyber Security News
Critical RCE Vulnerabilities in AI inference Engines Exposes Meta, Nvidia and Microsoft Frameworks Critical RCE Vulnerabilities in AI inference Engines Exposes Meta, Nvidia and Microsoft Frameworks Cyber Security News
Ransomware Operations Surge Following Qilin’s New Pattern of Attacks Ransomware Operations Surge Following Qilin’s New Pattern of Attacks Cyber Security News
VMware Fusion Flaw Allows Root Access Escalation VMware Fusion Flaw Allows Root Access Escalation Cyber Security News
FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof Cyber Security News
Windows 11 Update Resolves Bluetooth Visibility Bug Windows 11 Update Resolves Bluetooth Visibility Bug Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark