The attack "bypasses two-factor authentication (2FA) through session hijacking and real-time credential interception." ...