#mfa


Rogue external MFA providers can steal passwords during logins

Sep 23, 2026 // 00:56

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users’ passwords during legitimate login attempts. […]

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Sep 9, 2026 // 17:29

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers […]

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Sep 7, 2026 // 18:57

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers […]

Password spraying attacks surge 155x as hackers exploit MFA gaps

Aug 19, 2026 // 17:17

Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving […]

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Aug 10, 2026 // 18:40

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable […]

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Aug 5, 2026 // 00:28

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber […]

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

Jul 22, 2026 // 09:41

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used […]

New phishing kits target Microsoft 365 accounts, evade MFA

Jul 14, 2026 // 15:56

Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). While Jalisco […]

Webinar: How attackers bypass MFA and how defenders can respond

Jun 19, 2026 // 15:16

Many organizations view multi-factor authentication as one of their strongest defenses against account compromise. However, attackers increasingly use phishing techniques that don’t require stealing passwords […]

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Jun 15, 2026 // 22:49

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot […]

1 2 Next