threat-intel The MFA Identity Trap: When Authentication Creates a False Sense of Security Multi-factor authentication (MFA) is increasingly relied upon, but organizations are mistakenly assuming that successful MFA automatically verifies a user’s identity. Attackers are exploiting vulnerabilities in the processes surrounding authentication – like account recovery and device registration – to bypass MFA and… SecurityWeek · 4d ago High mfaidentity-proofingauthentication
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st) This script identifies users within an organization who have not yet been enrolled in multi-factor authentication (MFA) using the Microsoft Graph API. It leverages a beta command to efficiently list un-registered users,… SANS Internet Storm Center · Aug 21, 2026 Info mfamicrosoftgraph
threat-intel Curiouser and Curiouser Cisco Talos has identified "JWR", a new phishing framework and variant of "The Outsider" as a service, used to steal payment data, 2FA codes, and device fingerprints via SMS lures impersonating regional authorities. The… Cisco Talos · Aug 13, 2026 High phishingsmsmfa
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
threat-intel Inside the Modern SOC: The Identity Front Door A significant trend in cyberattacks is the increasing reliance on compromised identities rather than exploiting technical vulnerabilities. Nearly 90% of Unit 42 investigations involved identity weaknesses, with 65% of in… Palo Alto Unit 42 · Aug 7, 2026 High identity theftcredential abusesocial engineering
threat-intel UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, direc… The Hacker News · Aug 7, 2026 High NOAUU.vishingphishingdata-breach
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 Device code phishing, a rapidly growing threat exploiting the OAuth 2.0 device authorization grant, has evolved from a niche technique to a widespread criminal and nation-state tactic in a matter of months. Attackers are… The Hacker News · Jul 31, 2026 High device-code-phishingoath2phishing-as-a-service
threat-intel You were onto something with “It’s the Climb,” Miley This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-… Cisco Talos · Jul 30, 2026 High USphishingauthenticationransomware
threat-intel Identity Attacks Overtake Exploits as Top Ransomware Cause Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. Despite widespread deployment of MFA (97… Dark Reading · Jul 15, 2026 High ransomwarephishingmfa
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Acc… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access
threat-intel What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Recent breaches attributed to the ShinyHunters cybercrime collective, including attacks on organizations like University of Nottingham and Medtronic, highlight a shift in cyberattack tactics. Attackers are increasingly t… SecurityWeek · Jun 22, 2026 High UKidentity-theftcredential-theftmfa
phishing Webinar: How attackers bypass MFA and how defenders can respond The article discusses a growing trend in cyberattacks where attackers bypass multi-factor authentication (MFA) through sophisticated phishing techniques, specifically Device Code phishing. These attacks exploit legitimat… BleepingComputer · Jun 19, 2026 High phishingmfaaccount takeover
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The 5 Best Practices for Secure Identity Verification This article from BleepingComputer highlights key best practices for organizations to strengthen their identity verification processes and improve overall cyber resilience. It emphasizes the growing threat of credential… BleepingComputer · Jun 10, 2026 High UKmfaidentity verificationauthentication