Tag

#MFA

41 stories taggedMFA.

Illustration: a glowing laptop keyboard at night with a faint holographic key hovering above the enter key
Identity & Access

Attackers Are Logging In, Not Breaking In

AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

4 min read
Illustration: a single smartphone lying flat on a plain concrete desk
Identity & Access

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.

A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

4 min read
A help desk operator's phone in their hand displaying a password reset request form, with a computer monitor behind showing multi-factor authentication dialogs,
Identity & Access

When Password Resets Become the Front Door: The Rise of Help Desk Attacks

Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

4 min read
A security operations center with multiple monitors displaying alert systems, one showing a SIM card symbol with warning indicators, another with an internation
Threat Intelligence

Invisible Characters, SIM Swap Jail Time, and a $10 Million Bounty: This Week's Security Briefing

A trick that hides malicious text from spam filters, a phone-hijacking criminal now behind bars, and a US government reward for help catching an Iranian hacking official.

3 min read
A corporate security operations center with large displays showing autonomous AI agent activities being monitored and controlled, security chiefs reviewing dash
AI Security

AI Agents Are the Biggest Security Headache for CISOs Right Now

A new survey of global security chiefs finds that controlling AI agents, which are software programs that act independently to complete tasks, has become the dominant worry in corporate security, far outpacing every other concern on the list.

3 min read
A power substation or electrical utility facility at night with transformer equipment illuminated, a computer terminal showing access logs in an office area, an
Breaches

CenterPoint Energy Confirms Customer Data Stolen After Hacker Posts 7.5 Million Records Online

A Houston electricity and gas supplier serving 7 million households has told federal regulators that an outsider broke into one of its internet-facing systems and walked off with customer personal information.

3 min read
A cybersecurity analyst working late into the evening, surrounded by monitors displaying vulnerability bulletins and exploit code, racing against time as clock
Identity & Access

Why knowing about a threat isn't the same as stopping it

Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

4 min read
A corporate office worker at a desk, illuminated by monitor light, typing credentials into a login form on their screen while unaware of malicious intent, with
Identity & Access

N0va phishing kit hunts logins across US and EU businesses

A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

4 min read
An email inbox on a computer screen with a message containing ASCII characters arranged in a pattern, some security filter indicators visible, and a phone camer
Identity & Access

The QR Code Hiding in Plain Text: This Week's Sneakiest Phishing Trick

Attackers built scannable QR codes out of typed characters to slip past image-blocking filters, while a trusted developer tool shipped credential-stealing code.

4 min read
A conference stage presentation setup with a podium facing rows of security professionals, demonstrating attack methodologies with code and terminal windows vis
AI Security

A Former Internet Godfather Explains How AI Gives Criminals a Head Start

Brett Johnson built some of the first organised online crime networks. Now he's showing security conferences exactly how fast AI lets attackers work, and why defenders are still catching up.

4 min read
An office environment with an employee at a computer appearing to provide unauthorized access credentials to someone off-screen, with sensitive network diagrams
Identity & Access

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door

Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

4 min read
Close-up of a router's ethernet ports glowing with activity lights, a single red warning indicator blinking among the green, dust settling on the device's venti
Threat Intelligence

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale

A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

4 min read
An office worker at a desk, face obscured, staring at a computer screen showing security alerts and suspicious login notifications during business hours
Identity & Access

When Google Workspace gets breached, the door is usually already open

Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

3 min read
A corporate network access point with multi-factor authentication confirmation displayed on screen, showing successful login while simultaneously an attacker ga
Identity & Access

Passing the Login Test Does Not Mean You Let In the Right Person

Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

3 min read
A smartphone screen showing an incoming call from an unknown number, with subtle security icons and dashboard glimpses visible in the background blur
Identity & Access

ShinyHunters phoned a ReliaQuest employee, and one of them fell for it

The security firm says a vishing call led to a view-only peek at its Okta dashboard, but device-trust rules stopped anything worse.

3 min read
© 2026 Threat Vectr