CSO Online reported a new phishing campaign designed to trick employees into bypassing Microsoft 365 MFA, underscoring that attackers continue to target identity controls through social engineering rather than purely technical exploits. In parallel, PayPal described efforts to move customers away from SMS-based MFA, reflecting broader industry recognition that SMS is vulnerable to interception, SIM swapping, and user manipulation, and that stronger phishing-resistant authentication options are increasingly necessary.
Other items in the set were not part of a single, specific incident: one was a broad weekly roundup mixing AI, deepfakes, ransomware, and policy items, and another was a career-focused feature for CISOs. A separate CSO Online piece on a NIST initiative related to agentic AI is policy/strategy-oriented and not directly tied to the Microsoft 365 phishing activity or PayPal’s MFA changes, so it does not materially contribute to an incident-level briefing on MFA bypass threats.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
PayPal was reported to be making a new effort to move away from SMS-based multi-factor authentication. The reference frames this as a current product and security initiative without more specific event timing.
A reported phishing campaign was highlighted that tricks employees into bypassing Microsoft 365 multi-factor authentication protections. The reference provides no further timing details beyond the publication window.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.