Tag: mfa
-
Wie Fertigungsunternehmen produktionskritische Systeme mit Mikrosegmentierung schützen
Produktionsnetze müssen verfügbar bleiben auch während Sicherheitsmaßnahmen eingeführt werden. Identitätsbasierte Mikrosegmentierung und Just-in-Time-MFA begrenzen seitliche Bewegungen im Netz, schützen privilegierte Zugriffe und beziehen Altsysteme ein, ohne die gewachsene OT-Infrastruktur grundlegend umzubauen. Drei Praxisbeispiele zeigen, wie sich Resilienz, Nachweisfähigkeit und Betriebssicherheit zusammenführen lassen. Mikrosegmentierung teilt die vernetzte Produktion in kontrollierbare Sicherheitszonen und begrenzt privilegierte… First seen…
-
Angreifer kapern Konten statt Systeme – MFA stoppt 79 Prozent der BEC-Angriffe nicht mehr
First seen on security-insider.de Jump to article: www.security-insider.de/business-email-compromise-mfa-identitaet-bec-studie-a-ea60be646943ada10f6a377e4a0dee10/
-
FBI’s CJIS v6.1: What Security Teams Need to Know.
The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/
-
Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data. The post Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-passkey-phishing-mfa-device-code/
-
AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats. AI-Powered RatHat Android Trojan Unlike traditional malware that relies on fixed scripts, RatHat offers a…
-
MFA Won’t Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse
-
Enterprise Access Management ohne Passwort – Das Passwort bleibt der wunde Punkt der Multi-Faktor-Authentifizierung
First seen on security-insider.de Jump to article: www.security-insider.de/enterprise-access-management-passwortlose-mfa-a-0e694deae39034091492046cf8cd306f/
-
Hersteller-Counter und großer Lounge-Bereich laden zu Fachgesprächen und Wissensaustausch ein
Die Sysob IT-Distribution präsentiert auf der it-sa 2026 in Nürnberg (Halle 7, Stand 512) Produktneuheiten seiner Herstellerpartner im Kontext aktueller Security-Herausforderungen wie NIS2, KI und digitale Souveränität. Im Fokus stehen dabei Lösungen zum Schutz von Identitäten, Endgeräten, Unternehmensdaten und Geschäftsanwendungen. Die vorgestellten IT-Sicherheitslösungen decken unter anderem die folgenden Technologiebereiche ab: Multi-Faktor-Authentifizierung, Identitätsmanagement, AI-Governance, Datensicherheit, Firewalls,…
-
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-passkey-phishing-microsoft-365-cloud-data/
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social…
-
Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft…
-
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
-
PassPasskey Bypasses MFA Without Breaking FIDO2
I have spent years arguing that passkeys are the right answer to phishing. The cryptography behind that argument is still sound. Research presented at Black Hat USA 2026 does not change it. What it changes is the assumption that deploying… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/pass-the-passkey-bypasses-mfa-without-breaking-fido2/
-
New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight…
-
AI-basierte Security-Operations-Center erkennen Ransomware nicht von selbst
Wie viele Analysten braucht das SOC-Team noch angesichts des Einzugs von künstlicher Intelligenz? Die Frage suggeriert die Antwort: Das AI-basierte Security-Operations-Center erfordert weniger Menschen. Leider sind die Unternehmen, die diese Frage stellen, meist genau diejenigen, die ihre Telemetrielücken, ihre ungesicherten Endgeräte oder ihre unzureichende MFA-Abdeckung noch nicht angegangen sind. Sie stellen sich vor, dass künstliche…
-
How vulnerable are single sign-on systems to modern credential attacks
Secure your SSO with phishing-resistant MFA and continuous monitoring. Learn to mitigate risks like session theft and credential sprawl to protect identity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-vulnerable-are-single-sign-on-systems-to-modern-credential-attacks-2/
-
PCI DSS 4.0 Audits: Continuum GRC Cybersecurity Assessments 2026
PCI DSS 4.0 compliance audits demand a fundamental shift from periodic checkbox exercises to continuous, risk-based cybersecurity assessments. Organizations preparing for 2026 assessments must address new requirements around targeted risk analyses, multi-factor authentication expansion, and automated security monitoring that directly impact how cardholder data environments are protected and validated. Key Takeaways: PCI DSS 4.0 introduces”¦…
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.Mirage2FA Campaign First seen on thehackernews.com Jump…
-
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey…

