Tag: mfa
36 articles

Cyber Firms' AI Defense Push Sparks Scrutiny Over Commitments
More than 200 companies, including tech giants like Microsoft and Google, have joined forces to supercharge cyber defense capabilities and shield against AI-enabled attacks. They're calling for a united front to share threat intel, track progress, and swiftly contain attacks.

WhatsApp Bolsters Sign-In Security with Multi-Device Passkey Support
Big news for WhatsApp users: you can now use multiple passkeys across iOS and Android devices to securely log into your account, making it even easier to protect yourself from phishing and account takeovers. This update allows you to manage multiple credentials directly in the app, streamlining your sign-in experience.

WhatsApp Bolsters Security with Multi-Passkey Support, Enhanced Verification
Boost your WhatsApp security with a game-changing update: you can now set up multiple passkeys across Android and iOS devices, adding an extra layer of protection to your account. Simply head to Settings > Account > Passkeys to get started!

Hackers Exploit MFA Gaps with 155x Surge in Password Spraying Attacks
Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Google Cloud Accelerates Post-Quantum Security Push with 2027 Milestone
Google Cloud is proactively bolstering its defenses against future quantum computer threats, aiming to complete a major milestone in its post-quantum security migration by 2027. The tech giant has mapped out a multi-year plan to adopt quantum-resistant cryptography, tackling key risks in data security and digital signatures.

Identity Takes Center Stage in Cybersecurity as Threats Evolve
In today's evolving threat landscape, protecting identity has become the top priority in cybersecurity - treat it like the crown jewels, because it is. By prioritizing identity protection and having a plan in place to recover quickly, organizations can safeguard the foundation of every mission.

Okta Bolsters Identity Security with Permiso Acquisition
Okta is taking identity security to the next level with its acquisition of Permiso Security, bringing together cutting-edge threat detection and response capabilities with its existing identity stack to provide unparalleled protection. This game-changing move will enable Okta to spot and respond to risks that emerge after users, machines, or AI-driven agents have authenticated.

Cyberattacks Expose Gaps in Organizational Readiness
Most organizations are unprepared to tackle a major cyberattack, with a staggering 73% admitting they'd struggle to respond effectively if one hit tomorrow. The real challenge lies not in having the right tools and plans, but in getting them to work seamlessly together under pressure.

Google Introduces Selfie-Based Account Recovery
Google just made account recovery a whole lot easier with its new selfie-based feature, allowing you to regain access to your account with a quick snap when other methods aren't an option. Simply record a short video on a device with a camera, and you're good to go!

Google Introduces Selfie Video Sign-in for Locked Accounts
Say goodbye to account lockouts! Google's new selfie video sign-in feature lets you register a short video of yourself and use a fresh recording to regain access to your account if you get locked out.

Zero Trust Bolsters Critical Infrastructure Against Identity Threats
A single compromised account, like the inactive VPN login used to breach Colonial Pipeline in 2021, can have devastating ripple effects - just imagine a national crisis triggered by a simple vulnerability. The Colonial Pipeline ransomware attack is a stark reminder of the catastrophic consequences that can unfold when critical infrastructure is compromised.

23andMe Agrees to $18m Settlement, New Data Security Mandates
After cracking down on 23andMe's lax security measures, a coalition of 42 US attorneys general, led by New York Attorney General Letitia James, has secured an $18 million settlement and binding data-protection commitments to safeguard customer information. This move comes after a 2023 data breach put millions of 23andMe customers at risk of having their personal info exposed.

Agencies Modernize Identity Infrastructure to Counter Emerging Threats
Federal agencies are racing against the clock to modernize their identity infrastructure, securing legacy systems while navigating the rapid evolution of AI and emerging post-quantum threats. As AI continues to advance at breakneck speed, agencies must build adaptable cybersecurity strategies to stay ahead of the threat landscape.

Microsoft Entra ID Shifts to Passkey Authentication Default
Microsoft is shaking things up with its Entra ID service by making passkey authentication the default method starting September 2026, and users currently relying on SMS or voice authentication will be automatically transitioned to passkeys. By February 1, 2027, SMS and voice authentication will be phased out, marking a significant shift towards more secure passkey technology.

Iran-Linked Hackers Deploy Cavern C2 Framework to Target Israeli Organizations
Iran-linked hackers have launched a sophisticated cyber attack campaign, dubbed Cavern Manticore, targeting Israeli organizations, particularly in the IT and government sectors, using a cutting-edge .NET-based framework. This threat cluster is affiliated with Iran's Ministry of Intelligence and Security, and its tactics overlap with other notorious groups like MuddyWater and Lyceum.

Banks Expose Accounts to Thieves by Making MFA Optional
Leaving multi-factor authentication optional has left countless bank accounts vulnerable to theft, with devastating consequences - just ask the 84-year-old victim who lost nearly $30,000 when thieves exploited this security gap. By making MFA optional, banks are inadvertently rolling out the red carpet for thieves.

WebAuthn Integration Breaches Windows RDP Security Gap
Prisma Browser's innovative team successfully integrated WebAuthn redirection into their RDP client, pioneering a secure solution that enables seamless authentication via local devices like YubiKey, Touch ID, or Windows Hello. This game-changing move closed a significant security gap in Windows RDP, paving the way for enhanced remote desktop security.

NCSC Offers Guidance on Thwarting Penetration Testers
Want to make life harder for hackers? The National Cyber Security Centre teamed up with penetration testers to share practical tips on building secure systems from the ground up.

MFA Rollout Exposes Invoicing Software Flaws
When implementing multi-factor authentication, even a well-planned rollout can hit snags, as seen in a recent case where an invoicing software flaw was exposed. A security expert and his team had agreed on a phased rollout plan with a customer to enable MFA across their Microsoft 365 tenancy.

Cybercriminals Worry AI Tools Will Disrupt Their Illicit Trade
Cybercriminals are getting anxious about the impact of AI tools on their illicit trade, and experts warn that now is the time for organizations to step up their cyber hygiene game with measures like timely patching, multifactor authentication, and passkey use. By prioritizing these defenses, businesses can stay ahead of emerging threats, including AI-assisted attacks.

ScarCruft Targets Microsoft Users with NarwhalRAT Malware
Beware of fake Microsoft account alerts! A sneaky North Korean hacking group, ScarCruft, is sending phishing emails that mimic Microsoft security notifications to trick you into downloading the NarwhalRAT malware.

Credential Theft Spurs Demand for Secure Identity Verification
Credential theft skyrocketed 160% in 2025, fueling a critical need for secure identity verification solutions that can outsmart AI-driven attacks. To stay ahead, robust multi-factor authentication is a must-have, combining unique factors like something you know, have, and are to fortify defenses.

AI Agents Expose Security Risks in 93% of Organizations
Most organizations are unwittingly rolling out AI agents with access to sensitive tasks, leaving them vulnerable to security breaches. In fact, only 32% of teams feel very confident they could recover from exposed admin credentials, highlighting a disturbing gap in control and preparedness.

Ukraine's Cybersecurity War: Resilience Trumps Reaction
In the face of uncertainty, cybersecurity experts can develop essential habits through practice, brainstorming, and preparation, turning crisis response into muscle memory. By focusing on preparation, resilience, and self-reliance, organisations and individuals can build the instincts needed to navigate turbulent times.