Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy.