When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure

When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure

•

Episode description

When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure

Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy.

Chapters

  • Introduction Mauven introduces two critical developments: active phishing kits defeating Microsoft 365 MFA and AI-assisted attack infrastructure built in minutes. These trends signal a fundamental shift for UK businesses relying on MFA as primary defence.
  • Jalisco and OmegaLord: When MFA Is No Longer the Answer Detailed examination of two operational phishing kits using adversary-in-the-middle proxying and device code abuse to defeat MFA on Microsoft 365. Explains why UK professional services firms are disproportionately exposed and outlines immediate mitigations including Conditional Access policies, FIDO2 keys, and token lifetime controls.
  • Call to Action Mauven asks listeners to follow the show and share it with anyone relying solely on MFA for Microsoft 365 protection.
  • AI Is Doing Ninety Per Cent of the Work Now Analysis of documented research showing a jailbroken Gemini model building a functional command-and-control server in six minutes. Discusses implications for UK SMBs as attack infrastructure becomes trivially easy to deploy at scale.
  • Briefly Noted: SAP and Joomla SAP’s July 2026 patch addresses sixteen vulnerabilities including three critical flaws. Actively exploited Joomla extension vulnerabilities with CVSS 10.0 scores threaten UK SMB websites, particularly older professional services and hospitality sites.
  • What to Do Today Four prioritised actions: verify Microsoft 365 Conditional Access configuration, patch Joomla extensions, review SAP July patches, and brief staff on device code authentication requests. Emphasises urgency of the MFA bypass issue.
  • Outro Mauven summarises that MFA alone is insufficient for Microsoft 365 and that Conditional Access policies and phishing-resistant authentication are now baseline requirements.

Links