Skip to main content

Tag: mfa bypass

195 articles

Empty office cubicle with laptop, monitor, and papers, set against a blurred cityscape backdrop.

Google Workspace Security Must Adapt to AI-Driven Threats

The traditional attack chain is getting a makeover: instead of starting with a malicious email, attackers now use OAuth apps to breach Google Workspace, exploiting new vulnerabilities in an AI-driven threat landscape. It's time to shift from an inbox-centric to an OAuth-first security approach to stay ahead.

Analyst 207
Employees work at desks in a modern, brightly-lit office setting with laptops and phones.

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts

RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

Analyst 207
Network server room with out-of-focus laptop in foreground.

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections

Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Analyst 207
Dimly lit server room with computer equipment and a security camera.

Akira Ransomware Affiliate Foiled by Evasion Tactic

Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Analyst 207
Blurred laptop on reception desk in brightly-lit office lobby with large window.

Ransomware Attacks Pivot to Identity-Based Exploits

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Analyst 207
Technicians work in a network operations center with modern and legacy equipment, including a Fortinet device.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Analyst 207
Cluttered office desk with laptop showing Windows login or blue screen, surrounded by papers and supplies near a window.

Akira Ransomware Gang Foiled by Safe Mode Reboot

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Analyst 207
Cluttered home office desk with laptop, smartphone, and notebook, cityscape visible through window.

DeadLock Ransomware Exploits Polygon Smart Contracts

DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Analyst 207
Control room with industrial panels, meters, and switches, and a cellular antenna outside a large window.

Hackers Exploit Private Cellular Network to Breach Polish Power Plant Controls

In a chilling breach, hackers infiltrated a Polish power plant's controls, putting the heat supply of 50,000 residents at risk, by exploiting a vulnerable private cellular network used to connect remote equipment. The intruder's route began at a nearby wind farm, where a poorly secured VPN and lack of multi-factor authentication created an easy entry point.

Analyst 207
Blurred laptop screen on cluttered office desk with hand hovering over keyboard.

AI Compresses Identity Attacks, Forces Device Trust Reassessment

Identity security is buckling under the strain of increasingly sophisticated threats, with stolen credentials remaining a top vulnerability - a whopping 44.7% of breaches involve compromised login details. AI is now compressing the time and effort attackers need to launch identity attacks, forcing a urgent reevaluation of device trust.

Analyst 207
Person looks concerned at mobile phone with blurred figure in help-desk uniform in background.

UNC6671 Targets SaaS Data with Vishing Attacks

Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Analyst 207
Person's hand reaching for laptop keyboard in office setting.

Microsoft 365 Phishing Campaign Hijacks Accounts to Gather Payroll, Finance Emails

Beware of a sneaky Microsoft 365 phishing campaign that's hijacking accounts to get its hands on sensitive payroll and finance emails. Hundreds of organizations across healthcare, education, and more have already been targeted in this financially driven attack.

Analyst 207
Laptop on a beige office desk with a blurred screen in a cubicle near a window.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access

Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Analyst 207
Person holding iPhone in coffee shop, looking down at device with blurred cityscape behind.

WebKit Flaws Compromise Apple iCloud Private Relay

Researchers have discovered a sneaky way for hackers to bypass iCloud Private Relay's protections and expose your real network address, putting your online privacy at risk. This vulnerability lets malicious actors send traffic directly from your device, revealing your hidden IP address.

Analyst 207
Law enforcement officer walks past blurred computer equipment outside a courthouse.

Snowflake hacker pleads guilty to massive data extortion scheme

In a major win for justice, Connor Moucka, a Canadian national, has pleaded guilty to masterminding a massive data extortion scheme targeting Snowflake customer environments, a case that could put him behind bars for up to 32 years. The guilty plea marks a significant milestone in one of the most expansive data-theft-and-extortion campaigns of 2024.

Analyst 207
Empty corporate boardroom with wooden table, high-backed chairs, and whiteboard, lit by natural light.

Identity Attacks Expose Gaps in APAC's Cyber Defenses

Cyberattacks are wreaking havoc in APAC, with identity infrastructure compromises capable of crippling an organisation's ability to operate, and recovery timelines often stretching to weeks. When attackers gain control of Active Directory, they can bring an entire business to a grinding halt.

Analyst 207
Rows of server racks in a modern office background with a laptop screen in the foreground.

AI-Powered Phishing Outpaces Blocklist Defenses

Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Analyst 207
Person looks concerned while viewing a laptop screen in a home office setting.

Phishing Scam Exploits Bank of America Brand to Install Remote Access Malware

Stay safe from phishing scams by being cautious of email origins and link destinations - it's your first line of defense against attacks like the recent Bank of America phishing scam. Pay attention to these details to avoid falling victim to remote access malware.

Analyst 207
Office setting with phone and laptop on a table, surrounded by mid-tone decor and daylight.

Phishing Service Greatness Exploits RingCentral to Target Microsoft 365 Accounts

A recent security bulletin from RingCentral may have inadvertently given hackers a blueprint for a phishing campaign, as a notorious phishing service known as Greatness has begun targeting Microsoft 365 accounts with sophisticated attacks. Greatness, a phishing-as-a-service platform, has upgraded its tactics to include advanced threats like adversary-in-the-middle attacks and device-code phishing flows.

Analyst 207
Cluttered home office desk with a laptop displaying a malware warning, surrounded by papers and everyday objects.

Malware Exploits Google Passkey Sync Flaws

Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Analyst 207
Laptop and smartphone on cluttered desk with blurred screen and malware code on nearby paper.

Malware Exploits Google Passkey Ecosystem for Account Takeover

Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

Analyst 207
SonicWall SMA 1000 series appliance in an office setting with network closet door ajar.

INC Ransomware Exploits SonicWall SMA 1000 Flaws in Global Campaign

INC Ransomware has rapidly become a major player in the cyber threat landscape, exploiting SonicWall SMA 1000 flaws to claim a staggering 885 victims worldwide as of August 2, 2026. The group's activity has surged since early August, with multiple victims listed on its data leak site.

Analyst 207
Guest on laptop in hotel lobby with authentication prompt on screen.

Hotel Wi-Fi Hijacked to Deliver Surveillance Malware

Hackers have found a sneaky way to hijack hotel Wi-Fi, using a simple trick to redirect guests to a fake login page that can deliver surveillance malware and even bypass multi-factor authentication. This clever hack starts with attackers taking control of a hotel's Wi-Fi gateway, allowing them to forge DNS answers and route traffic to their own servers.

Analyst 207
Person sitting at laptop in library looks concerned at login screen.

Device Code Phishing Threat Explodes as OAuth Attacks Bypass MFA

In just four weeks, Barracuda detected a staggering 7 million device-code phishing attacks, revealing a rapidly escalating threat that's bypassing traditional security measures. This sneaky technique exploits the OAuth 2.0 device authorization grant to steal access tokens, outsmarting even multi-factor authentication.

Analyst 207