Attackers beat MFA with AiTM proxies, stolen session cookies, and push fatigue. See why browser-level defense stops what identity controls cannot.