BigBear 2.0 Steals Microsoft 365 Sessions After MFA

π‘MFA did not stop BigBear 2.0βlearn how stolen Microsoft 365 cookies bypass the login step.
β‘ 30-Second TL;DR
What Changed
CloudSEK found 5,137 credential records, 4,148 session cookies, and 1,032 plaintext passwords in the BigBear 2.0 panel.
Why It Matters
BigBear 2.0 lowers the skill barrier for adversary-in-the-middle attacks and makes MFA completion alone insufficient protection against session hijacking. AI companies managing sensitive model, cloud, or customer data should treat stolen session tokens as a critical access risk.
What To Do Next
Require phishing-resistant FIDO2/WebAuthn authentication for Microsoft 365 administrator and developer accounts, and revoke active sessions when suspicious sign-ins are detected.
Key Points
- β’CloudSEK found 5,137 credential records, 4,148 session cookies, and 1,032 plaintext passwords in the BigBear 2.0 panel.
- β’At least 474 records showed completed MFA logins where attackers captured the resulting authenticated session.
- β’The operation used Evilginx2 reverse proxies and country-matched residential proxies to evade location-based checks.
- β’Custom phishing-page code attempted to disable FIDO2/WebAuthn and steer victims toward weaker authentication methods.
Weekly AI Recap
Read this week's curated digest of top AI events β
πRelated Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Computerworld β
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.