Skip to main content

Tag: mfa bypass

195 articles

Rows of shelved medical supplies in a distribution center with employees checking a laptop.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack

McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Analyst 207
Person sitting at laptop in quiet home office with blurred screen.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Analyst 207
Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

Microsoft Teams Targeted in Voice Phishing Campaigns

Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

Analyst 207
Laptop on a table displays a blurred Chrome Web Store page surrounded by out-of-focus software boxes.

Malicious Chrome Extensions Expose Crypto, Browser Data Theft

Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Analyst 207
Person sits at desk with laptop displaying blurred CAPTCHA prompt on screen.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Analyst 207
Employees work at desks in an office, one looking concerned, with a cityscape visible through a large window.

Botnets Leverage AI, Public Infrastructure in Sophisticated Attacks

A sneaky botnet called Dysphoria has compromised nearly 296,000 devices, paving the way for a wave of clever attacks that use social engineering and public infrastructure to catch victims off guard. One recent impersonation campaign even tricked employees into handing over credentials with a fake single sign-on page and a convincing phone call.

Analyst 207
Office workspace with computers and subtle network hints, laptop screen visible.

Phishing Kit NovaCookies Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Meet NovaCookies, a sneaky phishing kit that's being sold for just $320 a month, and can hijack your Microsoft 365 sessions in real-time by cleverly intercepting Docusign notifications. This live adversary-in-the-middle relay captures active sessions, allowing hackers to harvest your credentials and multi-factor authentication codes.

Analyst 207
Large, empty server room with rows of server racks and natural light pouring in through tall windows.

Snowflake Tackles Identity Debt as Passwords Lose Favor

The alarming rise of identity debt has led Snowflake to take a bold stance against outdated password practices, proactively tackling the vulnerabilities that leave businesses exposed. By phasing out password authentication, Snowflake is revolutionizing identity debt management and setting a new standard for secure data protection.

Analyst 207
Smartphone sits on retail store counter amidst blurred customer activity.

AnonyMousKIT Phishing Service Exploits Voice AI to Harvest iPhone Passcodes

Meet AnonyMousKIT, a sneaky phishing service that's exploiting voice AI to trick iPhone users into spilling their passcodes, fueling a massive operation with over 500 domains and 168 reseller brands. This clever scam uses stolen device info to craft convincing emails and texts that help crooks unlock stolen Apple devices.

Analyst 207
A cluttered office cubicle with laptop, phone, and papers, with a blurred cityscape in the background and a person's hand…

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation

Meet ZeroTokens, a sneaky phishing platform that's sending shockwaves with its real-time attack adaptation capabilities, allowing live operators to steer victims through a multi-stage scam. Over 45,000 phishing messages have already been sent to 24,000 recipients across 700 organizations, making it a threat that's hard to ignore.

Analyst 207
Person in modern office looks concerned at blank smartphone screen.

Recruiter Scams Target Corporate Credentials on Mobile Devices

Beware of recruiter scams targeting your corporate credentials on mobile devices! A recent discovery by Zimperium uncovered a sneaky phishing campaign impersonating top employers and recruiters, including Amazon, Apple, and Louis Vuitton, to steal sensitive info.

Analyst 207
Typical office desk with laptop and smartphone, blurred screens, in ordinary office setting with daylight.

Mirage2FA Campaign Targets 4,500 Firms, Bypasses Microsoft 365 2FA

Thousands of companies, including 4,532 unique organizations worldwide, have been targeted by the Mirage2FA campaign, a sneaky phishing-as-a-service toolkit that cleverly bypasses Microsoft 365's two-factor authentication. US-based companies are among the hardest hit, making up 63.7% of the victims.

Analyst 207
Cybersecurity professionals gather around a laptop and whiteboard in a brightly-lit office conference room.

ReliaQuest Exposes ShinyHunters' Social Engineering Tactics

ReliaQuest sets the record straight: claims of a ransomware attack or breach are completely false. The company recently thwarted a social engineering scheme by ShinyHunters, swiftly investigating and publicly rebutting the misinformation.

Analyst 207
Brightly-lit office setting with desk, chair, phone, and computer workstation.

ReliaQuest Foils ShinyHunters' Data-Theft Attack via Social Engineering

ReliaQuest swiftly foiled a sneaky social engineering attack by ShinyHunters, who tried to trick employees into spilling sensitive info, but thankfully, only had view-only access and didn't touch customer data. The company's quick response contained the threat, protecting its systems and customers from harm.

Analyst 207
Blurred laptop and smartphone screens on a quiet office desk, suggesting a secure login page.

Notion Abused to Harvest Authentication Tokens in Targeted Attacks

Researchers uncovered a sneaky phishing campaign where attackers abused Notion to steal authentication tokens, using free accounts to impersonate senior executives and send legit-looking document-sharing notifications. This clever tactic was linked to two phishing-as-a-service platforms and over 600 malicious scripts.

Analyst 207
Secure server room with rows of computer servers and networking equipment.

Microsoft patches exploited Entra ID flaw amid rising attacks

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Analyst 207
Person sitting at a coffee shop table looks concerned while holding a smartphone, surrounded by blurred cafe patrons and a…

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts

Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

Analyst 207
Employees work at desks in a modern office, one looking concerned and isolated.

Attackers Exploit Trusted Collaboration Platforms for Identity Abuse

Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

Analyst 207
Hospital corridor with people walking, computer workstation, and door in background.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

Analyst 207
Researcher in modern lab looks at laptop screen with concern.

Microsoft Copilot Exposes Vulnerability to Meta-Hacking

Researchers at Varonis Threat Labs uncovered a vulnerability in Microsoft Copilot, cleverly manipulating it to reveal its own weaknesses and craft a working attack, which they've dubbed CoSnitch. This surprising exploit was responsibly disclosed to Microsoft, which plans to issue a patch.

Analyst 207
A brightly-lit financial sector setting with a sense of unease, featuring a blurred laptop screen and empty whiteboard in…

BlackFile Targets Financial Firms in Ongoing Extortion Campaign

Financial firms are under attack by a relentless extortion group called BlackFile, which has been targeting the sector with alarming persistence since the start of the year. This threat actor has also set its sights on other industries, including med tech, with no signs of slowing down.

Analyst 207
A lone laptop sits on a table in an empty corporate office lobby or data center.

Azure Breach Exposes 3.6 Million Records from Top Companies

A threat actor known as TheHatman is selling employee data from top companies like McDonald's and Tata Consultancy Services, allegedly stolen from Microsoft Azure tenants using compromised credentials. The stolen records total 3.6 million, with McDonald's alone accounting for 1.7 million employee records.

Analyst 207
Laptop on a desk in a neutral office setting with blurred screen.

CTM360 Exposes Global Recruitment Phishing Campaign Using Browser-in-the-Browser Traps

Beware of a sneaky recruitment phishing scam that used fake interview pages and a clever Browser-in-the-Browser trick to steal Google and Facebook credentials from over 3,000 unsuspecting victims in just two months. This cunning attack even fooled multi-factor authentication, putting countless users at risk.

Analyst 207
French government office interior with blurred emblem in background.

French Tax Authority Confirms Data Breach After Hacker Touts 2M Records

The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

Analyst 207