#MFA
41 stories taggedMFA.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

When Password Resets Become the Front Door: The Rise of Help Desk Attacks
Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

Invisible Characters, SIM Swap Jail Time, and a $10 Million Bounty: This Week's Security Briefing
A trick that hides malicious text from spam filters, a phone-hijacking criminal now behind bars, and a US government reward for help catching an Iranian hacking official.

AI Agents Are the Biggest Security Headache for CISOs Right Now
A new survey of global security chiefs finds that controlling AI agents, which are software programs that act independently to complete tasks, has become the dominant worry in corporate security, far outpacing every other concern on the list.

CenterPoint Energy Confirms Customer Data Stolen After Hacker Posts 7.5 Million Records Online
A Houston electricity and gas supplier serving 7 million households has told federal regulators that an outsider broke into one of its internet-facing systems and walked off with customer personal information.

Why knowing about a threat isn't the same as stopping it
Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

N0va phishing kit hunts logins across US and EU businesses
A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

The QR Code Hiding in Plain Text: This Week's Sneakiest Phishing Trick
Attackers built scannable QR codes out of typed characters to slip past image-blocking filters, while a trusted developer tool shipped credential-stealing code.

A Former Internet Godfather Explains How AI Gives Criminals a Head Start
Brett Johnson built some of the first organised online crime networks. Now he's showing security conferences exactly how fast AI lets attackers work, and why defenders are still catching up.

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door
Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale
A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

Passing the Login Test Does Not Mean You Let In the Right Person
Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

ShinyHunters phoned a ReliaQuest employee, and one of them fell for it
The security firm says a vishing call led to a view-only peek at its Okta dashboard, but device-trust rules stopped anything worse.