< ciso
brief />
Tag Banner

All news with #mfa tag

152 articles

FBI and Secret Service Warn of Ongoing FortiBleed

🔒 The FBI and US Secret Service warned administrators to harden Fortinet FortiGate firewalls and SSL VPN gateways after reporting the persistent FortiBleed campaign. Agencies cited SOCRadar data indicating 86,644 compromised devices across 194 countries and linked ransomware affiliates to use of stolen credentials. The notice details attacker techniques including credential stuffing, GPU-accelerated cracking, and creation of administrative accounts to maintain stealthy persistence. Organizations are urged to isolate affected hosts, perform threat hunting, reset credentials, enable phishing-resistant MFA, and follow CISA eviction guidance.
read more →

Microsoft warns AI compresses attack timelines

🔍 Microsoft’s 2026 Digital Defense Report warns that AI has allowed threat actors to compress parts of the cyber-attack lifecycle from days to minutes, pressuring defenders to adapt rapidly. The report highlights increased use of agentic models for vulnerability discovery, customized phishing, and bespoke malware, and calls for investment in AI-based defenses and stronger identity controls like phishing-resistant MFA.
read more →

Why common MFA methods no longer stop account takeovers

🔒 Organizations long celebrated multi-factor authentication as the key defense against account takeover, but the metric "MFA enabled" obscures crucial differences in technique. Push notifications, SMS one-time codes, and hardware keys all count equally on compliance reports despite offering vastly different protection levels. Push fatigue, SIM swap, and phishing/real-time proxy attacks routinely defeat push and OTP-based MFA. Newer, phishing-resistant standards like FIDO2 and passkeys provide origin-bound cryptographic protection that stops these attacks at the protocol level.
read more →

Deepfake threat outpaces enterprise readiness, report finds

🔍 Three quarters of cybersecurity leaders report encountering suspected deepfake incidents in the past year, with a quarter of those affected saying a single incident cost their organization over $1m. The 2026 Pindrop Deepfake Readiness Index highlights a widening gap between increasingly sophisticated AI-generated audio and video attacks and enterprise preparedness. Experts urge improved training, phishing-resistant controls like MFA, and heightened board-level awareness to mitigate financial and reputational damage.
read more →

AWS Endorses ASD Campaign to Require MFA

🔐 AWS supports the Australian Signals Directorate’s (ASD) Multi-factor authentication: Switch it on campaign and urges all customers to enable MFA. The post highlights that passwords alone are insufficient against phishing and credential-stuffing attacks and notes MFA blocks over 99% of password-based compromises. AWS describes its phased enforcement of MFA for root users across all account types and promotes phishing-resistant options like FIDO2 passkeys and security keys.
read more →

Rogue external MFA providers can steal passwords

🔒 Security researchers at Varonis Threat Labs have demonstrated an attack, dubbed TrustSink, that lets an attacker with a highly privileged Microsoft Entra account register a rogue external MFA provider to capture users' passwords during legitimate logins. The malicious provider displays a convincing copy of Microsoft's password prompt during the MFA step, captures credentials in plaintext, then returns a valid signed token so the login completes normally. The technique requires post-compromise access to Global Administrator or Authentication Policy Administrator privileges and can persist across password resets until the rogue provider is removed.
read more →

AI reshapes nation-state threat landscape for CISOs

🔒 The accelerating use of AI by nation-state actors is blurring lines between national-security and enterprise threats, forcing CISOs to integrate geopolitical risk into everyday security planning. Experts urge closer collaboration with government agencies while organizations must reassess whether they are strategic targets. Practical steps include planning to operate through compromises, reducing exposure with controls like zero trust and MFA, and securing board-level support for resilience investments.
read more →

Microsoft urges Entra ID migration to passkeys

🔐 Microsoft reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the retirement of SMS first-factor sign-ins in February 2027. Admins can also use QR code authentication, FIDO2 security keys, or other Entra ID-supported methods. The retirement affects workforce tenant authentication and not Azure AD B2C or Entra External ID scenarios. Microsoft provided guidance and tools, including a PowerShell scanner, to help identify impacted users.
read more →

Strengthen Fundamentals to Enable Next‑Gen Security

🔒 Effective cyber defense hinges on strong fundamentals rather than constantly chasing the latest tools. The author, a CISO with large-enterprise experience, argues that visibility, identity management, risk‑based prioritization, resilience and a common security language are core. Embracing AI and other innovations is valuable but only when built on these basics. Organizations should inventory assets, scale identity controls like MFA and passkeys, focus on crown-jewel protections, rehearse recovery plans, and translate technical risk into business terms.
read more →

AWS Builder ID adds recovery and third‑party MFA

🔐 AWS Builder ID now supports adding a recovery email and new self-service account recovery options to help users regain access without contacting support. You can reset forgotten passwords via primary or recovery email and restore access if an MFA device is lost by verifying both emails. Third-party sign-ins from Google, Apple, GitHub, or Amazon can now register MFA devices directly in AWS Builder ID, and users may permanently switch to an email/password sign-in if they lose a third-party account.
read more →

Amazon Cognito adds admin TOTP reset API

🔐 Amazon Cognito introduces an admin API operation to reset a user's time-based one-time password (TOTP) multi-factor authentication configuration. Administrators can remove the TOTP device association for users who lose access to their authenticator, enabling users to enroll a new device on next sign-in. This avoids recreating accounts to recover locked-out users and preserves enforced MFA policies. The feature is available in all AWS Regions and is accessible via the AdminDeleteSoftwareToken API through the AWS CLI, SDKs, or APIs; see the developer guide for details.
read more →

WhatsApp adds multiple passkeys and stronger 2FA

🔐 Meta announced new WhatsApp security features, including support for multiple passkeys per account to enable phishing-resistant sign-ins across iOS and Android. The company reported over 1 billion users now sign in with passkeys and added a full password option for two-step verification, replacing the previous six-digit PIN. Android users will also receive added call context for unknown callers, such as origin and shared groups. Settings for passkey management are available under Settings > Account > Passkeys.
read more →

WhatsApp strengthens account security with passkeys

🔐 WhatsApp is rolling out several account security improvements, including support for multiple passkeys and an upgraded two-step verification option. Users can now create separate passkeys per platform (Android and iOS) and replace the previous six-digit PIN with a longer alphanumeric password. The update also adds more context on call screens for unknown callers to help users spot potential scams.
read more →

Mirage2FA Surge: Microsoft 365 Session Hijacks Rise

🛡️ The Mirage2FA campaign (2024–2026) has impacted thousands of organizations by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication. ANY.RUN research links the activity to 4,532 unique organization domains, with 63.7% of victims in the US and others across multiple regions. Attackers steal passwords and session cookies to hijack authenticated sessions, enabling impersonation, fraud, and access to SSO-connected services.
read more →

ReliaQuest confirms failed data-theft attempt after breach

🔒 ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more →

CISO View: Security Fundamentals in the AI Era

🔒 Chris Betz argues that as AI amplifies both attacker and defender capabilities, organizations must reinforce core security controls rather than abandon them. He emphasizes layered defenses—MFA, Zero Trust, patching, and detection and response—and describes how AI accelerates vulnerability discovery, threat modeling, and remediation. CISOs should combine technical rigor with strategic leadership to align security with business goals.
read more →

Password spraying surge exploits MFA gaps

🔐 Huntress reported a 155x increase in password spraying in H1 2026, driven by a campaign abusing Azure CLI and IPv6 BYOIP ranges from LSHIY LLC. The attacker leveraged reused credentials and the deprecated ROPC OAuth grant to bypass MFA protections that were not applied to this flow. Rampant login attempts led to dozens of compromises while attackers rotated providers and IP ranges to evade blocking. Huntress recommends disabling ROPC, enforcing broad MFA and conditional access, and limiting Azure CLI access to necessary admins.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →