Topic: multi-factor authentication

  • ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft

    ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft

    The ShinyHunters gang is conducting a sophisticated voice phishing campaign, using social engineering to steal credentials and MFA codes by impersonating IT support and using real-time, interactive phishing kits. Attackers exploit compromised SSO accounts (e.g., Okta, Microsoft Entra, Google) to ...

    Read More »
  • Generative AI Supercharges Active Directory Attacks

    Generative AI Supercharges Active Directory Attacks

    Generative AI is making sophisticated password attacks cheaper, faster, and more accessible, fundamentally shifting the cybersecurity landscape by enabling highly targeted and efficient assaults on identity systems like Active Directory. AI-powered attacks leverage pattern recognition and adversa...

    Read More »
  • Master NIS2 Compliance: Secure Passwords & MFA

    Master NIS2 Compliance: Secure Passwords & MFA

    The NIS2 Directive is a critical EU regulation requiring medium and large organizations in key sectors to implement stringent security controls, with a major focus on robust identity and access management to combat credential-based attacks. Compliance is mandatory for qualifying organizations, an...

    Read More »
  • Hypervisors: The Hidden Ransomware Risk in Virtualization

    Hypervisors: The Hidden Ransomware Risk in Virtualization

    Hypervisors are a critical but often overlooked ransomware target, as a single compromise can jeopardize hundreds of virtual machines, with traditional security tools lacking visibility into this layer. Hypervisor-based ransomware attacks surged dramatically in late 2025, driven by groups like Ak...

    Read More »
  • Maximize Your Year-End Cybersecurity Budget

    Maximize Your Year-End Cybersecurity Budget

    Focus on strategic year-end budget allocation by identifying security gaps with the highest business risks, such as those threatening operations, customer data, or compliance, to build a case for future investments. Strengthen identity controls through measures like expanding multi-factor authent...

    Read More »
  • What Insurers Check in Your Identity Verification

    What Insurers Check in Your Identity Verification

    Insurers now prioritize identity verification and access management as key criteria for cyber insurance, with control maturity directly affecting insurability and coverage terms. Underwriters rigorously evaluate specific security measures like least privilege, multi-factor authentication, and pri...

    Read More »
  • Secure Your Exchange Server: CISA & NSA Best Practices

    Secure Your Exchange Server: CISA & NSA Best Practices

    A new cybersecurity framework from CISA and the NSA provides detailed steps to protect Microsoft Exchange Server installations from sophisticated threats, focusing on hybrid and on-premises environments. Key recommendations include restricting administrative access, enforcing multi-factor authent...

    Read More »
  • Barracuda Exposes Stealthy Microsoft 365 Phishing Kit

    Barracuda Exposes Stealthy Microsoft 365 Phishing Kit

    Whisper 2FA is a sophisticated phishing-as-a-service platform that has compromised nearly one million Microsoft 365 accounts by stealing login credentials and authentication tokens since July 2025. It employs a continuous credential theft loop that persistently prompts victims for multi-factor au...

    Read More »
  • CMC Issues Education Sector Guidance After Canvas Data Breach

    CMC Issues Education Sector Guidance After Canvas Data Breach

    The Canvas data breach affected approximately 160 UK higher education institutions and up to 9,000 globally, with threat actors stealing confidential course and user data, though the incident did not meet the Cyber Monitoring Centre's minimum threshold for categorization. The CMC's review found t...

    Read More »
  • Zero Trust Security: From Authentication to Trust

    Zero Trust Security: From Authentication to Trust

    The traditional security model based on a secure network perimeter is obsolete, replaced by the Zero Trust framework which operates on "never trust, always verify," assuming breaches are always possible and requiring continuous verification for all access requests. While multi-factor authenticati...

    Read More »
  • Middle East Brute-Force Attacks Surge in 2026

    Middle East Brute-Force Attacks Surge in 2026

    A sharp rise in brute-force attacks targeting network security appliances like firewalls and VPNs was observed in early 2026, with a dominant share of malicious traffic originating from the Middle East. These attacks highlight the critical targeting of internet-exposed edge devices, with over hal...

    Read More »
  • Microsoft warns travelers of hotel Wi-Fi security risks

    Microsoft warns travelers of hotel Wi-Fi security risks

    Microsoft warns of an active Russian-backed hacking campaign targeting hotel Wi-Fi networks, using fake Microsoft 365 login pages to steal credentials during peak summer travel. Cybersecurity expert Peter Tran advises travelers to verify they are on the hotel’s authentic network, and to treat any...

    Read More »
  • Securing Critical Infrastructure by Closing Identity Gaps

    Securing Critical Infrastructure by Closing Identity Gaps

    The Colonial Pipeline ransomware attack exploited an inactive VPN account lacking multi-factor authentication, shutting down fuel supplies across the U.S. East Coast and demonstrating how compromised credentials can cripple critical infrastructure. State-backed actors like Volt Typhoon target cri...

    Read More »
  • $30,000 GPU Password Cracking Test: Results

    $30,000 GPU Password Cracking Test: Results

    A benchmark test found that high-end consumer GPUs, like the Nvidia RTX 5090, significantly outperform expensive AI accelerators (Nvidia H200, AMD MI300X) in password-cracking speed, making specialized AI hardware a poor investment for this purpose. The primary organizational risk is not advanced...

    Read More »
  • NCSC Warns of WhatsApp and Signal Hacker Threat

    NCSC Warns of WhatsApp and Signal Hacker Threat

    The UK's National Cyber Security Centre warns of sophisticated cyberattacks, primarily by Russia-based actors, targeting high-profile individuals on encrypted messaging apps like WhatsApp and Signal for espionage. Attackers use deceptive techniques such as malicious links, QR codes, and impersona...

    Read More »
  • Corporate Data Theft: Cloud File-Sharing Sites Under Attack

    Corporate Data Theft: Cloud File-Sharing Sites Under Attack

    A cybercriminal group named Zestix is selling sensitive data stolen from dozens of organizations by exploiting compromised employee credentials on cloud file-sharing platforms. The breaches highlight systemic security failures, including a lack of multi-factor authentication and outdated password...

    Read More »
  • Insider Threats: Protecting Your Team from Cyber Attacks

    Insider Threats: Protecting Your Team from Cyber Attacks

    Cybercriminals are now infiltrating companies by impersonating IT professionals during hiring, using fabricated personas and deepfakes to gain trusted, privileged access to sensitive systems. The primary goals of these "fake workers" include severe data theft, financial fraud, and cyber espionage...

    Read More »
  • Cut IT Costs with Self-Service Password Resets

    Cut IT Costs with Self-Service Password Resets

    Self-service password reset (SSPR) solutions reduce IT support costs and improve security by allowing employees to independently handle login issues, freeing up help desk resources and minimizing productivity losses. Implementing SSPR addresses the financial burden of password resets, which can c...

    Read More »
  • Australian Consumer Trust Plummets as Security Fears Soar: Ping Identity

    Australian Consumer Trust Plummets as Security Fears Soar: Ping Identity

    Only 11% of Australian adults fully trust organizations with their digital identities, reflecting a significant decline in consumer trust driven by AI-related data security fears. Australians are increasingly concerned about AI-driven threats, with 82% more worried about data security than five y...

    Read More »
  • Coro 3.6: Simplify Operations for Resource-Strapped SMBs

    Coro 3.6: Simplify Operations for Resource-Strapped SMBs

    Coro has launched Coro 3.6, an AI-driven security platform designed to help small and medium-sized businesses strengthen cybersecurity without needing extensive IT resources. The platform integrates all security functions into a unified system, automatically analyzing and correlating threats to r...

    Read More »