#MFA
41 stories taggedMFA · page 3 of 3.

What is multi-factor authentication and why does it matter?
MFA blocks the vast majority of automated account takeovers, even when your password is already stolen.

What is phishing and how do you spot a phishing email?
Phishing is the most common way attackers steal credentials and money. Here is what the attack looks like and how to catch it before you click.

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In
A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins
A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

Your Business Is Not Too Small to Be an Iranian Hacker's Next Target
Groups linked to Iran's intelligence services are not hand-picking victims. They're scanning the internet for any door left unlocked, and a GPS company and a medical-device maker have already paid the price.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

The Service Desk Is the New Phishing Inbox
Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

The Perimeter Is Gone. Attackers Already Knew That.
Modern intrusions rarely crack the wall. They walk through the front door, wearing your credentials.