#mfa


Hackers bypass SonicWall VPN MFA due to incomplete patching

May 21, 2026 // 10:37

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. During the intrusions, […]

The New Phishing Click: How OAuth Consent Bypasses MFA

May 19, 2026 // 14:34

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five […]

Compromised Credentials Bypass MFA; Attackers Still Gain Access.

Apr 9, 2026 // 18:37

The data leak at Figure compromised 967,200 email accounts without relying on any software flaws. Understanding the implications of this, and why typical MFA solutions […]

Google Security Scam: New Malicious PWA Steals Logins and MFA Codes.

Mar 2, 2026 // 23:47

A sophisticated phishing campaign is currently using fake Google Account security pages to trick users into installing malicious Progressive Web Apps (PWAs). These apps are designed to steal […]