Tag: mfa bypass
195 articles

Google Workspace Security Must Adapt to AI-Driven Threats
The traditional attack chain is getting a makeover: instead of starting with a malicious email, attackers now use OAuth apps to breach Google Workspace, exploiting new vulnerabilities in an AI-driven threat landscape. It's time to shift from an inbox-centric to an OAuth-first security approach to stay ahead.

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts
RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections
Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Akira Ransomware Affiliate Foiled by Evasion Tactic
Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Ransomware Attacks Pivot to Identity-Based Exploits
Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Akira Ransomware Gang Foiled by Safe Mode Reboot
In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

DeadLock Ransomware Exploits Polygon Smart Contracts
DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Hackers Exploit Private Cellular Network to Breach Polish Power Plant Controls
In a chilling breach, hackers infiltrated a Polish power plant's controls, putting the heat supply of 50,000 residents at risk, by exploiting a vulnerable private cellular network used to connect remote equipment. The intruder's route began at a nearby wind farm, where a poorly secured VPN and lack of multi-factor authentication created an easy entry point.

AI Compresses Identity Attacks, Forces Device Trust Reassessment
Identity security is buckling under the strain of increasingly sophisticated threats, with stolen credentials remaining a top vulnerability - a whopping 44.7% of breaches involve compromised login details. AI is now compressing the time and effort attackers need to launch identity attacks, forcing a urgent reevaluation of device trust.

UNC6671 Targets SaaS Data with Vishing Attacks
Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Microsoft 365 Phishing Campaign Hijacks Accounts to Gather Payroll, Finance Emails
Beware of a sneaky Microsoft 365 phishing campaign that's hijacking accounts to get its hands on sensitive payroll and finance emails. Hundreds of organizations across healthcare, education, and more have already been targeted in this financially driven attack.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access
Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

WebKit Flaws Compromise Apple iCloud Private Relay
Researchers have discovered a sneaky way for hackers to bypass iCloud Private Relay's protections and expose your real network address, putting your online privacy at risk. This vulnerability lets malicious actors send traffic directly from your device, revealing your hidden IP address.

Snowflake hacker pleads guilty to massive data extortion scheme
In a major win for justice, Connor Moucka, a Canadian national, has pleaded guilty to masterminding a massive data extortion scheme targeting Snowflake customer environments, a case that could put him behind bars for up to 32 years. The guilty plea marks a significant milestone in one of the most expansive data-theft-and-extortion campaigns of 2024.

Identity Attacks Expose Gaps in APAC's Cyber Defenses
Cyberattacks are wreaking havoc in APAC, with identity infrastructure compromises capable of crippling an organisation's ability to operate, and recovery timelines often stretching to weeks. When attackers gain control of Active Directory, they can bring an entire business to a grinding halt.

AI-Powered Phishing Outpaces Blocklist Defenses
Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Phishing Scam Exploits Bank of America Brand to Install Remote Access Malware
Stay safe from phishing scams by being cautious of email origins and link destinations - it's your first line of defense against attacks like the recent Bank of America phishing scam. Pay attention to these details to avoid falling victim to remote access malware.

Phishing Service Greatness Exploits RingCentral to Target Microsoft 365 Accounts
A recent security bulletin from RingCentral may have inadvertently given hackers a blueprint for a phishing campaign, as a notorious phishing service known as Greatness has begun targeting Microsoft 365 accounts with sophisticated attacks. Greatness, a phishing-as-a-service platform, has upgraded its tactics to include advanced threats like adversary-in-the-middle attacks and device-code phishing flows.

Malware Exploits Google Passkey Sync Flaws
Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Malware Exploits Google Passkey Ecosystem for Account Takeover
Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

INC Ransomware Exploits SonicWall SMA 1000 Flaws in Global Campaign
INC Ransomware has rapidly become a major player in the cyber threat landscape, exploiting SonicWall SMA 1000 flaws to claim a staggering 885 victims worldwide as of August 2, 2026. The group's activity has surged since early August, with multiple victims listed on its data leak site.

Hotel Wi-Fi Hijacked to Deliver Surveillance Malware
Hackers have found a sneaky way to hijack hotel Wi-Fi, using a simple trick to redirect guests to a fake login page that can deliver surveillance malware and even bypass multi-factor authentication. This clever hack starts with attackers taking control of a hotel's Wi-Fi gateway, allowing them to forge DNS answers and route traffic to their own servers.

Device Code Phishing Threat Explodes as OAuth Attacks Bypass MFA
In just four weeks, Barracuda detected a staggering 7 million device-code phishing attacks, revealing a rapidly escalating threat that's bypassing traditional security measures. This sneaky technique exploits the OAuth 2.0 device authorization grant to steal access tokens, outsmarting even multi-factor authentication.