Tag

#MFA

41 stories taggedMFA · page 2 of 3.

A local government housing authority office showing staff rebuilding cybersecurity defenses after a million-dollar wire transfer fraud, with security improvemen
Opinion

A Local Housing Authority Lost $1 Million to Email Fraud. Here Is What It Did Next.

A cybersecurity consultant's account of how a small government agency rebuilt its defences after criminals silently rerouted a wire transfer offers a practical road map for the thousands of local bodies running on skeleton IT crews.

4 min read
An email inbox interface showing multiple messages, with several appearing legitimate but flagged by security analysis tools, while an endpoint protection panel
Identity & Access

AI-powered phishing is slipping past email filters. Here's how to catch it after the click.

Email gateways can't spot every AI-written lure. The catch now happens at the identity and endpoint layer.

4 min read
A security operations center with massive wall displays showing login attempt metrics, graphs spiking dramatically upward, failed authentication patterns highli
Identity & Access

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots

Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

3 min read
A split comparison showing defensive AI systems on one side appearing robust and confident on dashboards, while actual attack simulations on the other side demo
AI Security

AI is already in your attacker's toolkit. Is it in your defences?

A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.

4 min read
A network diagram on a screen showing compromised VPN access points and failed encryption processes, ransomware code partially displayed with error messages, re
Ransomware

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom

The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

4 min read
A security operations center during a credential compromise alert, multiple screens showing device fingerprinting data, biometric readings, and behavioral analy
Identity & Access

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.

AI is turbocharging phishing and credential theft, and the old signals that told a company a login was fine are quietly failing. Here is what is replacing them.

4 min read
A security research lab where laptops are positioned showing passkey authentication flows on their screens, with physical security keys scattered on the desk, r
Identity & Access

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login

Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

4 min read
A bank app interface showing a transaction history with unusual large purchases for digital services highlighted in red, alongside a customer service chat windo
Identity & Access

Metro Bank Customer Lost £14,000 to Fraudsters Who Used Stolen Money to Buy AI Chatbot Credits

A Sussex businessman spent months fighting to recover £14,244 after criminals raided his Metro Bank account and spent the proceeds on credits for Claude, Anthropic's AI chatbot. The case raises hard questions about whether banks are doing enough to catch unusual spending patterns before the money is gone.

3 min read
A conference room table with security personnel reviewing threat assessments and hardware security keys spread across documents, with Democratic National Commit
Policy & Regulation

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

5 min read
A laptop displaying a Snowflake cloud interface with financial transaction notifications and cryptocurrency wallet addresses visible on adjacent windows, police
Cloud Security

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people

Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

4 min read
AI security research lab with multiple screens displaying autonomous AI agent behavior monitoring, security boundaries and containment protocols visualized, res
AI Security

Why Locking Down What AI Agents Can Do Is Not Enough

A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

4 min read
A government office desk with federal compliance documents and updated patch management timelines, an AI-generated threat assessment report beside them, represe
Policy & Regulation

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.

A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

5 min read
Four different authentication bypass scenarios displayed across a split-screen interface, each showing a different vector of attack against multi-factor authent
Identity & Access

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)

Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

5 min read
A corporate office environment where a single login credential entry on a monitor suddenly grants access to multiple department folders and systems across the s
Identity & Access

SSO Is the New Skeleton Key. Criminals Have Noticed.

One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

4 min read
Windows 11 login screen displaying the new passkey system interface, with security research documents showing three discovered flaws spread across a desk beside
Identity & Access

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again

A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default sign-in method for hundreds of millions of users.

4 min read
© 2026 Threat Vectr