A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight The post New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password appeared first on IT Security Guru.
First seen on itsecurityguru.org
Jump to article: www.itsecurityguru.org/2026/09/02/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password
![]()

