Topic: multi-factor authentication
-
ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft
The ShinyHunters gang is conducting a sophisticated voice phishing campaign, using social engineering to steal credentials and MFA codes by impersonating IT support and using real-time, interactive phishing kits. Attackers exploit compromised SSO accounts (e.g., Okta, Microsoft Entra, Google) to ...
Read More » -
Generative AI Supercharges Active Directory Attacks
Generative AI is making sophisticated password attacks cheaper, faster, and more accessible, fundamentally shifting the cybersecurity landscape by enabling highly targeted and efficient assaults on identity systems like Active Directory. AI-powered attacks leverage pattern recognition and adversa...
Read More » -
Master NIS2 Compliance: Secure Passwords & MFA
The NIS2 Directive is a critical EU regulation requiring medium and large organizations in key sectors to implement stringent security controls, with a major focus on robust identity and access management to combat credential-based attacks. Compliance is mandatory for qualifying organizations, an...
Read More » -
Hypervisors: The Hidden Ransomware Risk in Virtualization
Hypervisors are a critical but often overlooked ransomware target, as a single compromise can jeopardize hundreds of virtual machines, with traditional security tools lacking visibility into this layer. Hypervisor-based ransomware attacks surged dramatically in late 2025, driven by groups like Ak...
Read More » -
Maximize Your Year-End Cybersecurity Budget
Focus on strategic year-end budget allocation by identifying security gaps with the highest business risks, such as those threatening operations, customer data, or compliance, to build a case for future investments. Strengthen identity controls through measures like expanding multi-factor authent...
Read More » -
What Insurers Check in Your Identity Verification
Insurers now prioritize identity verification and access management as key criteria for cyber insurance, with control maturity directly affecting insurability and coverage terms. Underwriters rigorously evaluate specific security measures like least privilege, multi-factor authentication, and pri...
Read More » -
Secure Your Exchange Server: CISA & NSA Best Practices
A new cybersecurity framework from CISA and the NSA provides detailed steps to protect Microsoft Exchange Server installations from sophisticated threats, focusing on hybrid and on-premises environments. Key recommendations include restricting administrative access, enforcing multi-factor authent...
Read More » -
Barracuda Exposes Stealthy Microsoft 365 Phishing Kit
Whisper 2FA is a sophisticated phishing-as-a-service platform that has compromised nearly one million Microsoft 365 accounts by stealing login credentials and authentication tokens since July 2025. It employs a continuous credential theft loop that persistently prompts victims for multi-factor au...
Read More » -
CMC Issues Education Sector Guidance After Canvas Data Breach
The Canvas data breach affected approximately 160 UK higher education institutions and up to 9,000 globally, with threat actors stealing confidential course and user data, though the incident did not meet the Cyber Monitoring Centre's minimum threshold for categorization. The CMC's review found t...
Read More » -
Zero Trust Security: From Authentication to Trust
The traditional security model based on a secure network perimeter is obsolete, replaced by the Zero Trust framework which operates on "never trust, always verify," assuming breaches are always possible and requiring continuous verification for all access requests. While multi-factor authenticati...
Read More » -
Middle East Brute-Force Attacks Surge in 2026
A sharp rise in brute-force attacks targeting network security appliances like firewalls and VPNs was observed in early 2026, with a dominant share of malicious traffic originating from the Middle East. These attacks highlight the critical targeting of internet-exposed edge devices, with over hal...
Read More » -
Microsoft warns travelers of hotel Wi-Fi security risks
Microsoft warns of an active Russian-backed hacking campaign targeting hotel Wi-Fi networks, using fake Microsoft 365 login pages to steal credentials during peak summer travel. Cybersecurity expert Peter Tran advises travelers to verify they are on the hotel’s authentic network, and to treat any...
Read More » -
Securing Critical Infrastructure by Closing Identity Gaps
The Colonial Pipeline ransomware attack exploited an inactive VPN account lacking multi-factor authentication, shutting down fuel supplies across the U.S. East Coast and demonstrating how compromised credentials can cripple critical infrastructure. State-backed actors like Volt Typhoon target cri...
Read More » -
$30,000 GPU Password Cracking Test: Results
A benchmark test found that high-end consumer GPUs, like the Nvidia RTX 5090, significantly outperform expensive AI accelerators (Nvidia H200, AMD MI300X) in password-cracking speed, making specialized AI hardware a poor investment for this purpose. The primary organizational risk is not advanced...
Read More » -
NCSC Warns of WhatsApp and Signal Hacker Threat
The UK's National Cyber Security Centre warns of sophisticated cyberattacks, primarily by Russia-based actors, targeting high-profile individuals on encrypted messaging apps like WhatsApp and Signal for espionage. Attackers use deceptive techniques such as malicious links, QR codes, and impersona...
Read More » -
Corporate Data Theft: Cloud File-Sharing Sites Under Attack
A cybercriminal group named Zestix is selling sensitive data stolen from dozens of organizations by exploiting compromised employee credentials on cloud file-sharing platforms. The breaches highlight systemic security failures, including a lack of multi-factor authentication and outdated password...
Read More » -
Insider Threats: Protecting Your Team from Cyber Attacks
Cybercriminals are now infiltrating companies by impersonating IT professionals during hiring, using fabricated personas and deepfakes to gain trusted, privileged access to sensitive systems. The primary goals of these "fake workers" include severe data theft, financial fraud, and cyber espionage...
Read More » -
Cut IT Costs with Self-Service Password Resets
Self-service password reset (SSPR) solutions reduce IT support costs and improve security by allowing employees to independently handle login issues, freeing up help desk resources and minimizing productivity losses. Implementing SSPR addresses the financial burden of password resets, which can c...
Read More » -
Australian Consumer Trust Plummets as Security Fears Soar: Ping Identity
Only 11% of Australian adults fully trust organizations with their digital identities, reflecting a significant decline in consumer trust driven by AI-related data security fears. Australians are increasingly concerned about AI-driven threats, with 82% more worried about data security than five y...
Read More » -
Coro 3.6: Simplify Operations for Resource-Strapped SMBs
Coro has launched Coro 3.6, an AI-driven security platform designed to help small and medium-sized businesses strengthen cybersecurity without needing extensive IT resources. The platform integrates all security functions into a unified system, automatically analyzing and correlating threats to r...
Read More »