#MFA
34 stories taggedMFA.

A Local Housing Authority Lost $1 Million to Email Fraud. Here Is What It Did Next.
A cybersecurity consultant's account of how a small government agency rebuilt its defences after criminals silently rerouted a wire transfer offers a practical road map for the thousands of local bodies running on skeleton IT crews.

AI-powered phishing is slipping past email filters. Here's how to catch it after the click.
Email gateways can't spot every AI-written lure. The catch now happens at the identity and endpoint layer.

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots
Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

AI is already in your attacker's toolkit. Is it in your defences?
A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom
The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.
As AI turbo-charges phishing and credential theft, the old signals that told a company 'this login is fine' are quietly failing. Here's what's replacing them.

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login
Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

Metro Bank Customer Lost £14,000 to Fraudsters Who Used Stolen Money to Buy AI Chatbot Credits
A Sussex businessman spent months fighting to recover £14,244 after criminals raided his Metro Bank account and spent the proceeds on credits for Claude, Anthropic's AI chatbot. The case raises hard questions about whether banks are doing enough to catch unusual spending patterns before the money is gone.

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack
Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable ways through it, and most organisations are leaving at least one door wide open.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default for hundreds of millions of users.