Tag: mfa
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
Identity Is Broken. Stop Trying to Fix It.
Tags: access, authentication, credentials, cryptography, data, identity, infrastructure, mfa, zero-trustFrom the earliest days of public-key cryptography and systems like Rivest-Shamir-Adleman (RSA), organizations have relied on identity and credentials to determine who can access IT environments, data, and applications. Over the decades, this infrastructure has undergone innovations like multi-factor authentication, single sign-on, identity providers, and zero-trust architectures. Then, there has been the emergence of various..…
-
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
-
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
-
Wie das ‘Bulletproof”-Kit Secure-EGateways und Multi-Factor-Authentification umgehen kann
Die Sicherheitsforscher des KnowBe4 Threat Labs haben eine aktive Phishing-Infrastruktur untersucht, die gezielt eine Schwachstelle klassischer E-Mail-Sicherheitsmechanismen ausnutzt. Das von den Angreifern selbst als ‘Bulletproof” bezeichnete Redirector-Kit versteckt die eigentliche Phishing-Infrastruktur hinter kompromittierten, legitimen Websites. Dadurch können schädliche Links Secure-E-Mail-Gateways (SEGs) und klassische URL-Reputationsprüfungen umgehen. Das Umgehen von SEGs ist jedoch nur ein sekundärer Vorteil.…
-
Phishing hinter legitimen Websites: ‘Bulletproof”-Kit trickst SEGs und MFA aus
Das ‘Bulletproof”-Phishing-Kit nutzt kompromittierte Websites, um E-Mail-Schutz zu umgehen. AiTM-Angriffe können zudem MFA-Sitzungen übernehmen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-hinter-legitimen-websites-bulletproof-kit-trickst-segs-und-mfa-aus/a46199/
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
Hackers Target Blackstone, CME and Other Wall Street Firms in Phone-Based Scam
Hackers targeted major financial firms with help-desk vishing and real-time MFA interception. Here’s how the campaign worked and how to respond. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-unc6671-financial-firms-vishing-extortion/
-
Hackers Impersonate IT Support to Breach Leading Financial Companies
Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens…
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.”Greatness supports AiTM [adversary-in-the-middle] credential and First seen on thehackernews.com…
-
How Vulnerable Are Single Sign-On Systems to Modern Credential Attacks?
SSO credential attacks explained: how vishing, MFA resets, stale OAuth tokens and admin takeover break SSO, and the controls that stop each one. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-vulnerable-are-single-sign-on-systems-to-modern-credential-attacks/
-
Why SSO and data governance should be planned together in enterprise SaaS
Learn how SSO, SCIM, RBAC, MFA, and audit logs strengthen enterprise data governance, improve data security, and support trusted data management. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-sso-and-data-governance-should-be-planned-together-in-enterprise-saas/
-
Enterprise Security Checklist for New SaaS Companies: From Domain Registration to Single Sign-On
Learn the essential security practices every SaaS startup should implement, including SSO, SCIM, MFA, email authentication, audit logs, and continuous monitoring. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/enterprise-security-checklist-for-new-saas-companies-from-domain-registration-to-single-sign-on/
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Infostealer liefern die Token für EntraAngriffe – So umgehen Angreifer mit gestohlenen Token die MFA
First seen on security-insider.de Jump to article: www.security-insider.de/session-token-mfa-umgehen-a-99c3ed934040d76954f5e70496a3f1c1/
-
How SSO and SCIM help ad monetization platforms scale
Learn how SSO, SCIM, RBAC, MFA, and tenant isolation help ad monetization platforms scale securely while meeting enterprise identity requirements. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/how-sso-and-scim-help-ad-monetization-platforms-scale/
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/

