#MFA
34 stories taggedMFA · page 2 of 3.

What is multi-factor authentication and why does it matter?
MFA blocks the vast majority of automated account takeovers, even when your password is already stolen.

What is phishing and how do you spot a phishing email?
Phishing is the most common way attackers steal credentials and money. Here is what the attack looks like and how to catch it before you click.

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In
A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins
A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

Your Business Is Not Too Small to Be an Iranian Hacker's Next Target
Groups linked to Iran's intelligence services are not hand-picking victims. They are scanning the internet for any door left unlocked, and a GPS company and a medical-device maker have already paid the price.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into — and many victims had multi-factor authentication switched on, just not set up correctly.

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

The Service Desk Is the New Phishing Inbox
Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

MFA Alone Won't Save You: What Modern Attackers Know That Defenders Don't
A practitioner-focused webinar examines how threat actors sidestep conventional detection controls and why single-layer authentication assumptions are failing organizations.

Zero Trust Turns 15 and Still Can't Get Out of Its Own Way
The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

First-Day Passwords Are Still IAM's Soft Underbelly
Temporary onboarding credentials keep showing up in breach forensics. The problem isn't laziness — it's that most IT teams never actually defined what 'temporary' means.

Infostealers Are Now the Front Door for Ransomware Gangs
Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.

Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
A pro-Iran Telegram channel published a walkthrough showing how Instagram's conversational recovery assistant could be talked into linking attacker-controlled email addresses to target accounts. The Obama White House and a senior U.S. Space Force account were briefly defaced.