The Kratos phishing kit stole Microsoft 365 session cookies to bypass MFA entirely. Here’s exactly how that attack works, and the practical steps that actually reduce the risk.
Tag:
session hijacking
-
-
A high-severity stored cross-site scripting (XSS) vulnerability has been discovered in the MyCourts application, a platform used for tennis court booking and league management. This vulnerability, assigned CVE-2025-57424, affects the …