< ciso
brief />
Tag Banner

All news with #mfa tag

152 articles · page 2 of 8

AWS Security Agent adds email-based MFA pentesting

🛡️ AWS Security Agent (now part of AWS Continuum) can now automate penetration testing for applications that use email-based multi-factor authentication. The agent generates a unique forwarding address per credential so MFA messages can be routed to it via an email provider rule, allowing the agent to read and submit codes or links during a test without storing email account credentials. This complements existing TOTP support and is available in all Regions where the agent is supported.
read more →

AI Elevates Need for Cybersecurity Fundamentals

🔒 AI-driven tools are exposing long-standing security gaps while accelerating familiar attack techniques. Experts stress that core practices—identity management, patching, configuration hygiene, multifactor authentication, and zero-trust—remain essential and must be applied consistently. AI increases speed, scale, and customization of attacks, but does not eliminate the need for human oversight, judgment, and accountability.
read more →

AiTM Phishing Now Leading Entry Point for Law Firms

🛡️ eSentire's legal sector report shows Adversary-in-the-Middle (AiTM) phishing is now the primary initial access vector for law firms, responsible for 28.57% of incidents and surpassing conventional credential theft. The firm also noted a 20% YoY rise in attacks against legal organizations, with credential and identity-focused threats comprising 56.3% of all activity. The report highlights specific services and lures—such as the Tycoon2FA platform, ClickFix fake browser-error campaigns, and Microsoft Teams abuse—and urges adoption of phishing-resistant MFA like FIDO2 and conditional access controls.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →

South Korea reveals MFA training system data breach

🔒 South Korea's National Diplomatic Academy's online education system was breached after an exploited server vulnerability, allowing unauthorized access from April 2025 through February 2026. At least 6,000 individuals were affected, including around 350 current overseas attachés; Korean media suggests the number may be higher. Leaked fields reportedly include IDs, names, email addresses, and encrypted passwords, while sensitive identifiers and contact details were not exposed. The MFA has taken the system offline, strengthened security, and urged affected individuals to report suspicious communications.
read more →

23andMe to Pay $18M After Massive Genetic Data Breach

🔒 A coalition of 43 state attorneys general reached an $18 million settlement with 23andMe (now Chrome Holding Co.) over a 2023 data breach that exposed genetic data of 6.9 million customers. Investigators found the company lacked basic protections against credential-stuffing attacks, including multifactor authentication, password blocklisting, and adequate monitoring. The settlement imposes new security requirements, governance measures, and preserves consumer deletion rights while following prior lawsuits and fines.
read more →

Cybersecurity Needs More Prevention, Less Cure

🛡️ Cybersecurity has drifted toward detection-first solutions, yet prevention remains more cost-effective and impactful. The industry invests heavily in visibility, alerting and response—metrics like mean-time-to-detect dominate—while compromise is often treated as inevitable. The author urges renewed emphasis on blocking threats through measures like phish-resistant MFA, segmentation and proactive patching, arguing that prevention reduces noise, lowers long-term costs, and strengthens overall security posture.
read more →

Microsoft Entra ID makes passkeys default by 2026

🔐 Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, automatically enabling them for users currently relying on SMS and voice MFA. Those phone-based methods will be retired as native Entra capabilities on February 1, 2027, though organizations can use third-party telecom providers if needed. Users already on phishing-resistant methods like Windows Hello for Business, FIDO2 keys, or smart cards can continue using them without change.
read more →

New phishing kits target Microsoft 365 and evade MFA

🛡️ Two new phishing kits, Jalisco and OmegaLord, are being used to target Microsoft 365 accounts and bypass multi-factor authentication. Jalisco leverages the OAuth 2.0 device-code flow to trick victims into authorizing attacker-controlled devices, while OmegaLord poses as a PDF reader to harvest credentials and phone numbers. Researchers at ReliaQuest analyzed both toolkits and found attackers quickly exfiltrate data from SaaS platforms before demanding extortion. The report recommends tightening device-registration limits and blocking device-code authentication to reduce risk.
read more →

NHS warns staff over unlawful access to records

🔒 The NHS has warned staff they may face criminal prosecution and career-ending sanctions for accessing patient records without a legitimate reason. Head of the NHS Jim Mackey called such behaviour a “disgraceful breach of patient trust,” and the organisation has launched an awareness campaign alongside guidance for monitoring and preventing unauthorized access. The guidance urges technical controls such as least-privilege, MFA and role-based access, and notes real-time flags in modern electronic patient record systems. High-profile incidents and ICO action have prompted the drive to strengthen detection and deterrence.
read more →

SMB Cyber Readiness: Prioritize the Fundamentals

🔒 AI is reshaping attacker toolkits, but familiar failures—phishing, unpatched vulnerabilities, poor monitoring and weak passwords—remain the primary causes of incidents for SMBs. ESET telemetry and research show AI mainly amplifies these risks rather than replacing them with pervasive, real-time AI malware. Practical mitigations like patch management, identity protection, MFA, password managers and MDR services remain the most effective ways to improve readiness and resilience.
read more →

NCSC guidance to frustrate penetration testers

🔒 The NCSC asked pen testers what makes their work harder and published recommendations to boost organisational resilience. Responses emphasise secure-by-design practices—like threat modelling, phishing-resistant MFA, avoiding hard-coded credentials, and early input validation—alongside network segmentation and strong OT/IT separation. The guidance also highlights the critical role of quality logging, monitoring and exercised incident response to detect and respond to intrusions.
read more →

Why attackers target your email inbox aggressively

📧 Email accounts act as hubs for identity verification, password resets and long-term records, making them prime targets for cybercriminals. Attackers use phishing, account takeover, forwarding rules and abused tokens to maintain access, intercept codes and harvest sensitive information. Corporate inbox breaches can lead to data theft, ransomware or expensive fraud, while sophisticated tools like GenAI increase phishing success rates. Regularly review security settings, use MFA or passkeys, and remain vigilant to reduce risk.
read more →

CMC analysis of Canvas incident impacts education

🔍 The UK Cyber Monitoring Centre (CMC) has published its review of the Canvas incident affecting Instructure’s Learning Management System, finding ~160 UK higher education institutions impacted and around 9,000 worldwide. The analysis highlights that financial losses arose mainly from response, recovery and risk management rather than prolonged outage. The CMC reinforced best-practice recommendations for the sector, including MFA enforcement, separation of application and data layers, careful third‑party control and clearer vendor communication.
read more →

Cybersecurity’s Shift From Protection to Survival

🔒 The piece argues that cybersecurity must move beyond a prevention-first mindset to a survival-focused discipline. It stresses that while traditional controls (MFA, patching, hardening) remain necessary, organizations need breach readiness: continuity, recoverability, tested incident response, and clear governance. Regulatory and market pressures (EU resilience laws, US disclosure and accountability) plus AI-driven acceleration make resilience an operational imperative.
read more →

CISA Urges Fortinet Users to Secure Devices Now

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Fortinet customers to secure devices after nearly 74,000 firewall and VPN credentials were exposed in a leak dubbed "FortiBleed." The agency advised terminating SSL VPN and admin sessions, resetting passwords, enabling phishing-resistant multifactor authentication, and reviewing logs for signs of unauthorized access. CISA also recommended using PBKDF2 for admin credential storage and restricting management interfaces from the public internet.
read more →

Human behavior shapes cybersecurity outcomes

🛰️ Cisco Talos' Threat Source newsletter reflects on how human behavior, context, and competing priorities often override rational security decisions. The piece links a Spielberg film theme to cybersecurity, noting that knowledge alone doesn't ensure action — organizations struggle with budgets, workloads, and urgency. Talos highlights practical controls like segmentation, backups, and MFA, and showcases a new reverse-engineering method that pairs local AI agents with tools like vbdec to accelerate analysis while protecting sensitive binaries.
read more →

JLR CISO Ordered In-Person Password Resets

🔒 At Infosecurity Europe, Ashish Shrestha, then group CISO of Jaguar Land Rover, recounted the September 2025 cyber-attack response that required over 30,000 staff to reset passwords on site. He said the in-person resets ensured trusted identities for communications after the incident and validated Microsoft 365 integrity. The firm also reset MFA and validated users’ identities physically to mitigate risks of remote account takeover.
read more →

Protecting children's data to prevent long-term identity harm

🔒 Children face lasting identity and privacy risks online from school accounts, gaming profiles, apps and devices. These data can be exploited for fraud or synthetic identity creation, often remaining undetected for years. Parents, schools and vendors all share responsibility; practical steps include data minimization, strong passwords, MFA, privacy settings, parental controls and credit freezes.
read more →

AI Support Bot Exploit Lets Attackers Hijack Instagram

🔒 A wave of account takeovers targeted high-profile Instagram profiles after attackers shared instructions for tricking Meta’s AI support assistant into relinking accounts to attacker-controlled email addresses. The technique, circulated on Telegram on May 31, reportedly involved using a VPN to appear from the target’s locale, initiating a password reset, and persuading the AI bot to add a new email. Meta acknowledged a brief compromise of a dormant Obama White House account and pushed an emergency patch while asserting no backend database was breached. Experts warn AI-driven support flows introduce new attack surface and recommend strong MFA such as passkeys or security keys to mitigate risk.
read more →