Skip to main content

Tag: mfa bypass

195 articles

Modern law firm reception area with laptop and smartphone on desk.

AiTM Phishing Overtakes Credential Theft as Top Law Firm Threat

Law firms are under siege from a new type of phishing attack, with AiTM phishing now accounting for 28.57% of initial access events in the sector, overtaking conventional credential theft as the top threat. This sophisticated attack method has become the go-to tactic for hackers, bypassing even multifactor authentication defenses.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit cloud data center or server room with ambient lighting.

Azure Flaw Exposes Platform-Wide Key to All Databases

Microsoft patched a vulnerability in Azure Cosmos DB, dubbed CosmosEscape, which exposed a platform-wide key to all databases, but fortunately, no customer data was accessed and no action is required. The flaw was discovered by security firm Wiz, which detailed the exploit chain that could be used to take advantage of the vulnerability.

Analyst 207
Laptop on a desk in a bright office setting displays a notification on a Microsoft Teams interface.

Phishing Campaign Exploits Microsoft Authentication

Cyber attackers have found a sneaky new way to steal corporate accounts by exploiting Microsoft's authentication process, making it harder to spot fake requests. They've been sending emails that look like Microsoft Teams notifications, leading victims to a legitimate Microsoft URL that tricks them into granting access.

Analyst 207
Network equipment sits on a rack in a neutral-colored tech room with visible cables.

SonicWall VPNs Targeted in Rapid Credential Stuffing Campaign

In a shocking 41-hour blitz, hackers launched a massive credential stuffing campaign that compromised 92 unique user accounts across 30 organizations using SonicWall VPNs. The rapid attack, which started on Saturday and abruptly ended on Monday, left a trail of breached accounts in its wake.

Analyst 207
University hallway with open doors, symbolizing vulnerabilities in single sign-on security.

SSO Security Requires Proactive Defense Against Credential Attacks

A single compromised SSO account can become a master key, unlocking a vast array of sensitive services and putting millions of individuals at risk, as seen in the 2025 University of Pennsylvania breach where 1.2 million people's data was stolen. Proactive defense against credential attacks is crucial to protecting your organization's security.

Analyst 207
Blurred laptop screen shows Microsoft Teams on a brightly-lit office desk with another monitor or paper in the background.

Phishing Campaign Operation BlueDash Targets Teams Users with RMM Tools

Beware of Operation BlueDash, a sneaky phishing campaign that tricks Microsoft Teams users into downloading malicious RMM tools by masquerading as a genuine Microsoft Store update. Victims are cleverly directed to a fake store page that claims Teams needs to be updated to access a shared document.

Analyst 207
Person working at desk with laptop and smartphone, surrounded by papers in a home office with city view.

Insurance Phishing Evolves Into Real-Time Account Hijacking

Insurance phishing attacks have taken a sinister turn, now using real-time account hijacking to actively engage with victims throughout the authentication process. Cybercriminals are using sponsored Google ads to launch these attacks, luring users with offers like car insurance comparisons and then diverting them into sophisticated phishing flows.

Analyst 207
Empty office with computer workstation, papers, and supplies, cityscape visible through window.

Russian Espionage Group Exploits Zimbra Flaw to Steal Western Data

A single, stealthy view is all it takes for hackers to exploit a Zimbra flaw, allowing them to siphon off 90 days' worth of emails, passwords, and sensitive data. This alarming vulnerability, tracked as CVE-2025-66376, has prompted a joint warning from US and international cybersecurity officials.

Analyst 207
Concerned office worker holding a smartphone at their desk surrounded by papers and office supplies.

Ransomware Attacks Intensify as AI Enhances Phishing Tactics

Ransomware attacks are getting smarter and more effective, with AI-powered phishing tactics leading to a significant increase in successful breaches. In fact, 65% of organizations hit by ransomware say AI tools made the attack more convincing and effective.

Analyst 207
Person sitting at laptop with concerned expression, surrounded by papers and notes in a home office with natural daylight.

Identity Theft Exposes Vulnerability in Email Account Security

Giving a scammer a two-factor authentication code can have devastating consequences, as one unfortunate account owner discovered when it allowed the scammer to take over their email address. This simple mistake opened the door to a broader security risk, highlighting a vulnerability in email account security.

Analyst 207
Corporate office interior with employees working, featuring a large blank whiteboard in the foreground.

Ransomware Risk Amplified by Enterprise GenAI Deployments

With enterprise GenAI deployments on the rise, the ransomware risk is skyrocketing - after all, Microsoft alone detects over 38 million identity risk signals daily, a stark reminder that AI-enabled attacks can strike at any moment. As attackers supercharge their ops with AI, businesses are unwittingly increasing their vulnerability by deploying AI systems that can be exploited.

Analyst 207
Person sitting at desk with laptop and smartphone, Adobe Acrobat extension open on screen.

Adobe Acrobat Extension Flaw Exposes WhatsApp Web Chats

A newly discovered vulnerability in the Adobe Acrobat extension for Chrome, known as HermeticReader, could allow hackers to access your WhatsApp Web conversations with just one visit to a malicious webpage. No clicks, logins, or cookies required - making it a shockingly easy exploit to carry out.

Analyst 207
Businessperson looks concerned while staring at laptop screen in office setting.

Ransomware gangs exploit victims' payments, extort again

Paying ransomware attackers doesn't always guarantee relief, with many victims being extorted again. A recent survey found 54% of organizations globally paid a ransom, yet it often doesn't end the attack.

Analyst 207
Law enforcement officials stand near seized computer equipment in a brightly lit facility.

Authorities Disrupt Kratos Phishing Platform in Global Operation

In a major global crackdown, authorities have shut down Kratos, a notorious phishing-as-a-service platform that helped cybercriminals create fake Microsoft login pages to steal sensitive info. The takedown has disrupted a key tool used by over 1,800 customers to commit crimes like business email compromise and data theft.

Analyst 207
Blurred computer screen amidst ordinary office equipment and decor suggests disruption.

Ransomware Attacks Exploited Compromised Identities in 79% of Incidents

Ransomware attacks are often sparked by something surprisingly simple: 79% of incidents start with compromised identities, highlighting the vulnerability of legitimate user logins and credentials. This means that in nearly 8 out of 10 cases, attackers gain a foothold using stolen or hijacked identities rather than complex hacking techniques.

Analyst 207
Government agency public area with podium and blurred video on screen.

FBI Warns of Deepfake Videos Targeting IC3 Leadership

Impersonation scams have taken a chilling turn, with scammers now using deepfake videos and AI-generated content to convincingly pose as government officials, including senior FBI leadership. These sophisticated cons combine social media impersonation, fake complaint portals, and high-fidelity videos to re-target previous fraud victims.

Analyst 207
Hand reaches for Android smartphone with blurred lock screen on a flat surface.

Google scrambles to fix Android bug that lets Gemini bypass lock screen security

Google is racing to squash a newly discovered Android bug that allows sneaky users to bypass lock screen security and send SMS or WhatsApp messages using Gemini, all without entering the device PIN. A fix has already been implemented and is set to roll out this week.

Analyst 207
Chrome browser window on laptop showing Claude extension interface with workflow process.

Claude Extension Flaw Exposes AI Actions to Malicious Extensions

A security researcher discovered a vulnerability in Anthropic's Claude browser extension that allows malicious Chrome extensions to trick it into performing predefined AI actions on connected services like Gmail and Google Docs. This flaw could have serious consequences, as it only requires a simple simulated click to launch built-in workflows.

Analyst 207
Rack-mounted SonicWall SMA1000 appliance in a typical office server closet.

Attackers Exploit Zero-Days in SonicWall Appliances

Cyber attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall appliances, with ransomware attacks seemingly their ultimate goal. Rapid7's team has thwarted attempts at data exfiltration and encryption, but the threat remains.

Analyst 207
Person at desk with laptop and hardware wallet, laptop screen blurred, wallet app shows suspicious recovery page.

OkoBot Malware Targets Hardware Wallets with Seed Phrase Phishing

Beware of OkoBot malware, a sneaky threat that's been targeting hardware wallet users since April 2025, tricking hundreds of victims in over 25 countries into divulging their seed phrases through clever phishing tactics. This malicious software can even infiltrate legitimate wallet apps like Ledger and Trezor, replacing their interfaces with fake recovery pages.

Analyst 207
Office worker sits at desk with laptop, showing subtle concern on face.

Ransomware Attacks Surge Through Compromised Logins

Ransomware attacks are surging, with a staggering 79% of incidents linked to compromised identities and legitimate user logins, making it the most common entry point for hackers. This marks a significant shift away from traditional software flaw exploitation, now accounting for just 18% of initial attacks.

Analyst 207
Laptop on cluttered desk with Google Docs open, surrounded by papers and notes in a home office setting.

Claude for Chrome Flaw Exposes Gmail, Google Docs to Rogue Extensions

A security flaw in Claude for Chrome could put your Gmail, Google Docs, and Calendar at risk of being accessed by rogue extensions, with researchers rating the vulnerability as high-severity. A simple script with just six lines of code can trick the extension into treating a fake click as a genuine user action.

Analyst 207
Person looks concerned while examining a laptop screen with a fake security alert.

Phishers Target LastPass, Bitwarden Users with Fake Security Alerts

Beware of fake security alerts! LastPass and Bitwarden users are being targeted by phishers with convincing emails that mimic real corporate communications, trying to trick you into visiting fraudulent websites.

Analyst 207
Business setting with laptop on desk, papers and supplies nearby, and CRM system on screen.

Microsoft Tracks ShinyHunters' Salesforce Data Theft Via OAuth Flaws

Microsoft uncovered a sneaky year-long operation by the ShinyHunters extortion group, who exploited trust in Salesforce's OAuth system to steal sensitive data, using clever vishing tactics to trick employees into granting access to a malicious app. The attackers posed as IT support, convincing victims to authorize a fake Data Loader tool that allowed them to make API calls and search for valuable credentials.

Analyst 207