https://winbuzzer.com/2025/12/22/microsoft-365-phishing-surge-attackers-weaponize-legitimate-device-code-flow-to-bypass-mfa-xcxwbn/
Microsoft 365 Phishing Surge: Attackers Weaponize Legitimate Device Code Flow to Bypass MFA -...
Dec 22, 2025 - Cybercriminals have launched a widespread phishing campaign exploiting Microsoft's OAuth device code flow to bypass MFA and hijack accounts without passwords.
device code flowmicrosoft
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-enforce-mfa-for-microsoft-365-admin-center-sign-ins/
Microsoft to enforce MFA for Microsoft 365 admin center sign-ins
Microsoft will start enforcing multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center starting next month.
center signmicrosoftenforce
https://www.csoonline.com/article/3480918/design-flaw-has-microsoft-authenticator-overwriting-mfa-accounts-locking-users-out.html
Design flaw has Microsoft Authenticator overwriting MFA accounts, locking users out | CSO Online
May 8, 2025 - Microsoft stands out from the authenticator crowd by annihilating accounts when new accounts are introduced via QR code. Despite user complaints for years, no...
microsoft authenticatordesign
https://winbuzzer.com/2024/12/13/critical-microsoft-mfa-loophole-exposed-millions-of-user-accounts-xcxwbn/
Critical Microsoft MFA Loophole Exposed Millions of User Accounts - WinBuzzer
Dec 13, 2024 - A flaw in Microsoft Azure multi-factor authentication allowed attackers to brute-force accounts, exposing data in Teams, OneDrive, and more.
critical microsoftmfaloophole
https://www.paloaltonetworks.com/blog/sase/microsoft-mfa-vulnerability-stresses-need-for-strong-identity-posture/
Microsoft MFA Vulnerability Stresses Need for Strong Identity Posture - Palo Alto Networks Blog
Dec 16, 2024 - Organizations must adopt a layered approach to identity posture security—one that combines robust configurations with continuous oversight.
microsoft mfastrong identity
https://www.pcworld.com/article/3028542/all-microsoft-365-users-will-need-to-activate-mfa-soon-or-else.html
All Microsoft 365 users will need to activate MFA soon, or else | PCWorld
Jan 9, 2026 - Microsoft is forcing this move as a way to reduce account security risks and help safeguard user data.
microsoftusersneedactivatemfa