MFA fatigue and MFA bombing describe the same attack. Both mean flooding a user with authentication prompts until one is approved. Push bombing and MFA spamming are further names for it. There is no technical distinction worth drawing.
The terms differ only in emphasis. “Bombing” names the attacker’s action, the flood of requests. “Fatigue” names the human effect being exploited. Vendors have preferred different labels, which is why both persist.
What matters is that all the names require a prerequisite: the attacker already has a valid password. Prompts only arrive if the first factor succeeded.
Related: how to prevent MFA fatigue · MFA fatigue