Topic: multi-factor authentication
-
Google Ads API Mandates Multi-Factor Authentication
Google Ads will enforce mandatory multi-factor authentication (MFA) for all new user logins via its API starting April 21, 2026, enhancing account security. The requirement applies to new OAuth 2.0 authentications, prompting users to set up 2-step verification, but existing tokens and service acc...
Read More » -
Why Most Organizations Fail at MFA
Traditional MFA methods like SMS codes and push notifications are vulnerable to phishing and MFA fatigue attacks, making them insufficient against sophisticated adversaries. Organizations must adopt phishing-resistant hardware security keys (e.g., FIDO2 or WebAuthn) that use public-key cryptograp...
Read More » -
ShinyHunters' New MFA Bypass Fuels Data Theft
A sophisticated social engineering campaign is bypassing multi-factor authentication (MFA) using synchronized voice and email phishing attacks, successfully targeting major companies like Panera Bread and Match Group. Attackers, linked to groups like UNC6661 and ShinyHunters, use IT impersonation...
Read More » -
ownCloud Urges MFA Activation Following Credential Theft
ownCloud is urging all users to immediately enable multi-factor authentication (MFA) to block unauthorized access, even if login credentials are stolen. The company clarified its platform was not hacked; attackers instead used credentials stolen by malware from employee devices to access accounts...
Read More » -
Valorant's New MFA Update Cracks Down on Smurfing
Valorant's 11.09 update mandates multi-factor authentication for suspicious accounts in Competitive play to combat smurfing and account sharing, with plans to extend this to high-ranked players in specific regions. The patch introduces quality-of-life improvements, such as consistent green highli...
Read More » -
5 Best Practices for Secure Identity Verification
Credential theft surged 160% in 2025, now causing one in five data breaches due to AI-driven attacks, while organizations must balance robust identity verification with user convenience. Implementing fatigue-resistant multi-factor authentication (MFA) that combines different factor categories, su...
Read More » -
Protect Your SSO From Modern Credential Attacks
A compromised SSO account at the University of Pennsylvania in 2025 led to a breach of internal systems and theft of 1.2 million individuals' data, highlighting the high-value target SSO creates for attackers. To secure SSO, organizations must enforce strong, NIST-compliant passwords (at least 15...
Read More » -
MFA Bypass Leads to Major Infostealer Attack on 50 Firms
A major data breach affecting around 50 global companies was enabled by the lack of multi-factor authentication (MFA), allowing an attacker to use stolen credentials for cloud file-sharing platforms. The attacker, using credentials harvested by infostealer malware, accessed accounts where passwor...
Read More » -
Secure Active Directory with UserLock IAM: Product Showcase
UserLock is a modern IAM layer for Microsoft Active Directory that enhances security with granular MFA, contextual access rules, and real-time session monitoring without requiring a disruptive identity overhaul. It provides comprehensive visibility and control by aggregating AD entities into dash...
Read More » -
Cybersecurity Controls: How They Impact Incident Outcomes
Incident response planning, including tabletop exercises and red-team tests, significantly improves readiness and drives broader security investments. Endpoint detection and response (EDR) tools, especially when fully deployed and used in blocking mode, strongly correlate with reduced breach like...
Read More » -
Beyond Credentials: Why Device Trust Matters in the AI Era
AI has accelerated identity-based attacks by making phishing, credential theft, and MFA bypass faster and more scalable, while traditional trust signals like IP reputation and geolocation are now easily spoofed by attackers using residential proxies and rotating identities. Device trust is emergi...
Read More » -
Device Security Must Share the Load Beyond Identity
Identity verification alone is no longer sufficient for security, as AI-powered phishing, credential theft, and session hijacking allow attackers to bypass authentication and steal session tokens even after MFA succeeds. Zero Trust frameworks like NIST 800-207 warn against relying on implied trus...
Read More » -
Stop Password Reset Attacks: 7 Key Prevention Strategies
Password reset functions are a critical but often overlooked security vulnerability, providing attackers a path for privilege escalation and lateral movement within networks. Attackers exploit weak reset procedures through tactics like social engineering, token interception, and leveraging overly...
Read More » -
1Password's New Anti-Phishing Tool Protects Your Weakest Link
AI-powered phishing scams are creating sophisticated, convincing fake websites at scale, posing a significant threat to both individuals and corporations as a common entry point for attacks. 1Password's new phishing protection feature counters this by issuing a warning when users manually paste c...
Read More » -
6 Overlooked Okta Security Settings You Must Check Now
Securing identity providers like Okta is critical as they act as central gatekeepers for digital access, with risks arising from misconfigurations and evolving threats. The article outlines six essential Okta security practices, including robust password policies, phishing-resistant MFA, and feat...
Read More » -
Okta Users Targeted by Advanced Phishing & Vishing Kits
New phishing kits enable real-time credential interception and control of authentication flows, targeting users of major identity platforms like Google and Microsoft. These attacks combine voice phishing with dynamic, convincing fake login pages that bypass multi-factor authentication methods lik...
Read More » -
Stolen Police Logins Expose Flock Cameras to Hackers
Federal lawmakers are demanding an FTC investigation into Flock Safety's license plate scanning network due to its failure to mandate multi-factor authentication for all law enforcement users, leaving sensitive data vulnerable. Unauthorized access to Flock's system could allow hackers to exploit ...
Read More » -
AI Phishing Surge Sparks Cybersecurity Alarm in Australia
AI-driven phishing attacks are becoming more sophisticated and harder to detect, with 73% of Australians believing AI has increased the success of these scams. There is a significant gap between cybersecurity awareness and action, as 46% of Australians interacted with phishing messages in the pas...
Read More » -
Secure Your Network: NIS2 Password, MFA & AD Best Practices
The EU's NIS2 Directive mandates stricter cybersecurity measures, including robust risk management, proactive identity and access management, and continuous monitoring for compliance across various sectors. Strengthening Active Directory is essential under NIS2, as it centralizes authentication a...
Read More » -
Energy Firms Hit by Sophisticated AiTM Phishing Attacks
A sophisticated phishing campaign is targeting the energy sector using Adversary-in-the-Middle (AiTM) attacks, which bypass standard email filters and multi-factor authentication (MFA) by stealing login credentials and session cookies. Once an account is compromised, attackers establish persisten...
Read More »