Attackers bypassed multi-factor authentication through the non-MFA-compatible ROPC protocol because many organizations had incompletely configured their Conditional Access Policies.
Secure Boot certificates from 2011 expired on June 24, 2026; more will expire in October – updates to 2023 certificates fail on some devices, and Microsoft now provides error documentation.
New phishing campaigns exploit genuine Microsoft authentication dialogs to manipulate users into granting access authorization, bypassing password theft and multi-factor authentication.