< ciso
brief />
Tag Banner

All news with #mfa tag

137 articles

CISO View: Security Fundamentals in the AI Era

🔒 Chris Betz argues that as AI amplifies both attacker and defender capabilities, organizations must reinforce core security controls rather than abandon them. He emphasizes layered defenses—MFA, Zero Trust, patching, and detection and response—and describes how AI accelerates vulnerability discovery, threat modeling, and remediation. CISOs should combine technical rigor with strategic leadership to align security with business goals.
read more →

Password spraying surge exploits MFA gaps

🔐 Huntress reported a 155x increase in password spraying in H1 2026, driven by a campaign abusing Azure CLI and IPv6 BYOIP ranges from LSHIY LLC. The attacker leveraged reused credentials and the deprecated ROPC OAuth grant to bypass MFA protections that were not applied to this flow. Rampant login attempts led to dozens of compromises while attackers rotated providers and IP ranges to evade blocking. Huntress recommends disabling ROPC, enforcing broad MFA and conditional access, and limiting Azure CLI access to necessary admins.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

AWS Security Agent adds email-based MFA pentesting

🛡️ AWS Security Agent (now part of AWS Continuum) can now automate penetration testing for applications that use email-based multi-factor authentication. The agent generates a unique forwarding address per credential so MFA messages can be routed to it via an email provider rule, allowing the agent to read and submit codes or links during a test without storing email account credentials. This complements existing TOTP support and is available in all Regions where the agent is supported.
read more →

AI Elevates Need for Cybersecurity Fundamentals

🔒 AI-driven tools are exposing long-standing security gaps while accelerating familiar attack techniques. Experts stress that core practices—identity management, patching, configuration hygiene, multifactor authentication, and zero-trust—remain essential and must be applied consistently. AI increases speed, scale, and customization of attacks, but does not eliminate the need for human oversight, judgment, and accountability.
read more →

AiTM Phishing Now Leading Entry Point for Law Firms

🛡️ eSentire's legal sector report shows Adversary-in-the-Middle (AiTM) phishing is now the primary initial access vector for law firms, responsible for 28.57% of incidents and surpassing conventional credential theft. The firm also noted a 20% YoY rise in attacks against legal organizations, with credential and identity-focused threats comprising 56.3% of all activity. The report highlights specific services and lures—such as the Tycoon2FA platform, ClickFix fake browser-error campaigns, and Microsoft Teams abuse—and urges adoption of phishing-resistant MFA like FIDO2 and conditional access controls.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →

South Korea reveals MFA training system data breach

🔒 South Korea's National Diplomatic Academy's online education system was breached after an exploited server vulnerability, allowing unauthorized access from April 2025 through February 2026. At least 6,000 individuals were affected, including around 350 current overseas attachés; Korean media suggests the number may be higher. Leaked fields reportedly include IDs, names, email addresses, and encrypted passwords, while sensitive identifiers and contact details were not exposed. The MFA has taken the system offline, strengthened security, and urged affected individuals to report suspicious communications.
read more →

23andMe to Pay $18M After Massive Genetic Data Breach

🔒 A coalition of 43 state attorneys general reached an $18 million settlement with 23andMe (now Chrome Holding Co.) over a 2023 data breach that exposed genetic data of 6.9 million customers. Investigators found the company lacked basic protections against credential-stuffing attacks, including multifactor authentication, password blocklisting, and adequate monitoring. The settlement imposes new security requirements, governance measures, and preserves consumer deletion rights while following prior lawsuits and fines.
read more →

Cybersecurity Needs More Prevention, Less Cure

🛡️ Cybersecurity has drifted toward detection-first solutions, yet prevention remains more cost-effective and impactful. The industry invests heavily in visibility, alerting and response—metrics like mean-time-to-detect dominate—while compromise is often treated as inevitable. The author urges renewed emphasis on blocking threats through measures like phish-resistant MFA, segmentation and proactive patching, arguing that prevention reduces noise, lowers long-term costs, and strengthens overall security posture.
read more →

Microsoft Entra ID makes passkeys default by 2026

🔐 Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, automatically enabling them for users currently relying on SMS and voice MFA. Those phone-based methods will be retired as native Entra capabilities on February 1, 2027, though organizations can use third-party telecom providers if needed. Users already on phishing-resistant methods like Windows Hello for Business, FIDO2 keys, or smart cards can continue using them without change.
read more →

New phishing kits target Microsoft 365 and evade MFA

🛡️ Two new phishing kits, Jalisco and OmegaLord, are being used to target Microsoft 365 accounts and bypass multi-factor authentication. Jalisco leverages the OAuth 2.0 device-code flow to trick victims into authorizing attacker-controlled devices, while OmegaLord poses as a PDF reader to harvest credentials and phone numbers. Researchers at ReliaQuest analyzed both toolkits and found attackers quickly exfiltrate data from SaaS platforms before demanding extortion. The report recommends tightening device-registration limits and blocking device-code authentication to reduce risk.
read more →

NHS warns staff over unlawful access to records

🔒 The NHS has warned staff they may face criminal prosecution and career-ending sanctions for accessing patient records without a legitimate reason. Head of the NHS Jim Mackey called such behaviour a “disgraceful breach of patient trust,” and the organisation has launched an awareness campaign alongside guidance for monitoring and preventing unauthorized access. The guidance urges technical controls such as least-privilege, MFA and role-based access, and notes real-time flags in modern electronic patient record systems. High-profile incidents and ICO action have prompted the drive to strengthen detection and deterrence.
read more →

SMB Cyber Readiness: Prioritize the Fundamentals

🔒 AI is reshaping attacker toolkits, but familiar failures—phishing, unpatched vulnerabilities, poor monitoring and weak passwords—remain the primary causes of incidents for SMBs. ESET telemetry and research show AI mainly amplifies these risks rather than replacing them with pervasive, real-time AI malware. Practical mitigations like patch management, identity protection, MFA, password managers and MDR services remain the most effective ways to improve readiness and resilience.
read more →

NCSC guidance to frustrate penetration testers

🔒 The NCSC asked pen testers what makes their work harder and published recommendations to boost organisational resilience. Responses emphasise secure-by-design practices—like threat modelling, phishing-resistant MFA, avoiding hard-coded credentials, and early input validation—alongside network segmentation and strong OT/IT separation. The guidance also highlights the critical role of quality logging, monitoring and exercised incident response to detect and respond to intrusions.
read more →

Why attackers target your email inbox aggressively

📧 Email accounts act as hubs for identity verification, password resets and long-term records, making them prime targets for cybercriminals. Attackers use phishing, account takeover, forwarding rules and abused tokens to maintain access, intercept codes and harvest sensitive information. Corporate inbox breaches can lead to data theft, ransomware or expensive fraud, while sophisticated tools like GenAI increase phishing success rates. Regularly review security settings, use MFA or passkeys, and remain vigilant to reduce risk.
read more →

CMC analysis of Canvas incident impacts education

🔍 The UK Cyber Monitoring Centre (CMC) has published its review of the Canvas incident affecting Instructure’s Learning Management System, finding ~160 UK higher education institutions impacted and around 9,000 worldwide. The analysis highlights that financial losses arose mainly from response, recovery and risk management rather than prolonged outage. The CMC reinforced best-practice recommendations for the sector, including MFA enforcement, separation of application and data layers, careful third‑party control and clearer vendor communication.
read more →

Cybersecurity’s Shift From Protection to Survival

🔒 The piece argues that cybersecurity must move beyond a prevention-first mindset to a survival-focused discipline. It stresses that while traditional controls (MFA, patching, hardening) remain necessary, organizations need breach readiness: continuity, recoverability, tested incident response, and clear governance. Regulatory and market pressures (EU resilience laws, US disclosure and accountability) plus AI-driven acceleration make resilience an operational imperative.
read more →