#mfa — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mfa, aggregated by home.social.
-
Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA
Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.
Pulse ID: 6a7b418c9c13f8e6bf2c89c7
Pulse Link: https://otx.alienvault.com/pulse/6a7b418c9c13f8e6bf2c89c7
Pulse Author: cryptocti
Created: 2026-08-11 15:36:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti
-
Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA
Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.
Pulse ID: 6a7b418c9c13f8e6bf2c89c7
Pulse Link: https://otx.alienvault.com/pulse/6a7b418c9c13f8e6bf2c89c7
Pulse Author: cryptocti
Created: 2026-08-11 15:36:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti
-
Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA
The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
and device-code phishing to steal Microsoft 365 authentication tokens and
bypass MFA. Active campaigns exploit trusted sender configurations and
phishing lures to compromise accounts. Stolen tokens enable attackers to
access Outlook, Teams, SharePoint and OneDrive while evading
conventional authentication-based security controls.Pulse ID: 6a79bef48cee5cb15fd34fd2
Pulse Link: https://otx.alienvault.com/pulse/6a79bef48cee5cb15fd34fd2
Pulse Author: cryptocti
Created: 2026-08-10 12:07:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti
-
Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA
The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
and device-code phishing to steal Microsoft 365 authentication tokens and
bypass MFA. Active campaigns exploit trusted sender configurations and
phishing lures to compromise accounts. Stolen tokens enable attackers to
access Outlook, Teams, SharePoint and OneDrive while evading
conventional authentication-based security controls.Pulse ID: 6a79bef48cee5cb15fd34fd2
Pulse Link: https://otx.alienvault.com/pulse/6a79bef48cee5cb15fd34fd2
Pulse Author: cryptocti
Created: 2026-08-10 12:07:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti
-
📰 Attacker Pleads Guilty in Massive 2024 Snowflake Breach Campaign
Justice served: The primary attacker behind the massive 2024 Snowflake customer data breaches has pleaded guilty. The campaign exploited stolen credentials on accounts without MFA, exposing 100M+ records. #Snowflake #DataBreach #CyberSecurity #MFA
-
Why Your Salesforce Report Exports Are Failing and How to Fix It
If you are a sales or support operations expert on Salesforce, you most likely use the export feature under reports. When you want to do your own analysis and follow up on MS Excel or Google Sheets, or send the list to an external provider this feature comes to the rescue. Older Orgs have many periodic workflows executed by a variety of users that involve such steps.
If you have been following Salesforce Break, you know that there have been many security incidents involving Salesforce recently. When Salesforce rolled out the recent tightened security measures, many of these report export workflows started breaking down. Salesforce now requires a step-up authentication whenever a user wants to export or print report data.
If you have been using an AppExchange (now AgentExchange) App for your data exports, the chances are that they broke down as well. Salesforce started moving away from some of the legacy methods of downloading data; for example, they don’t support csv exports of report data any more.
If your App or integration provider keeps up with these recent requirements and turns them into updates, then you are in lock. There are still supported and secure ways of exporting your data out of Salesforce.
The Problem with the Native Salesforce Data Connector
Several major issues make the native connector difficult to use in a professional environment:
1. Authentication Hurdles
Step-Up Authentication often triggers when a user attempts to export reports, leading to constant re-authentication requests. Salesforce says API access should not initiate step-up requests, but the migration to tightened security measures has been very painful and inconsistent. For automated or scheduled sheets, the sync is likely to fail because the background process cannot satisfy the interactive MFA challenge.
2. Analytics API Limitations
Salesforce has moved toward the Analytics API as the primary data extraction method for many integrated apps. While modern, this API brings strict limitations that were less prominent in older methods. Most notably, users are often hitting a 2,000-row limit on report exports through this method. In an era of “Big Data,” a 2,000-row cap is an immediate dealbreaker for most financial, sales, or operational audits. There is also an Org-wide limit that amounts to about 3 million records capacity per hour. This number, while it sounds pretty large, can be reached very easily in large orgs.
3. Changing Security Landscape
Beyond the hard caps, reliability has become a major concern. Recent data breach incidents forced Salesforce to make quick changes out of their usual release cycles. These changes broke workflows and decreased the reliability of solutions that have been working for years. If you are an admin of a Salesforce Org, it may be a good idea to trust a reliable partner to keep up with these changes and adopt to the new secured architecture as the requirements change.
The Solution: G-Connector by Xappex
Here is how I used the G-Connector by Xappex:
Use case: Bring in a report to Google sheets and prepare a workflow that can manage high volume of records.Install the G-Connector Salesforce Sync Google Sheet Extension
Installing the G-Connector Google extension is fairly easy. You go to this link and install the extension by logging in with your Google Workspace username and password. You need to make sure that your Salesforce user is API-enabled. Once you authenticate, you go to the Salesforce Connected Apps OAuth Usage screen and install the Xappex connected app. This step should ensure that the connection can be established without issues in the future. Note that Xappex needs a few permissions, and these permissions will be listed for you to approve on both sides (Google and Salesforce).
Import Data (Or Export Data)
Import or export: it depends on where you’re standing, I guess. You’ll see these terms used interchangeably throughout the post.
Once you establish the org connection, go to Import Data / New from Report on the Xappex G-Connector extension. Choose the report you want to import from the pulldown showing all Salesforce reports. You can import all detail rows unformatted, or import the formatted report.
Future-Proof Your Workflow For Larger Volumes
The import went through without issues, but you are not sure what will happen when all users ask for report data in the future and/or the record count grows. To future proof your workflow, you can convert your report to SOQL and have Xappex pull the same data using the Salesforce API without involving reports. This feature, while still in beta, actually works very well. Click on the SOQL converter and generate the SOQL statement for your report.
Your workflow will not be subject to rate limits for the Analytics API now.
What does the Xappex G-Connector solution provide?
If you find yourself manually copying and pasting data to bypass the recently-added road blocks, it’s time to consider an enterprise-grade alternative. G-Connector by Xappex was designed to solve the exact pain points that the native connector can not cope with.
As a robust, professional-tier integration, G-Connector offers several advantages:
- Solid Reliability: Xappex actively maintains G-Connector to stay ahead of Salesforce’s updates, including MFA and authentication changes, ensuring your data flows without interruption.
- High Efficiency: While native tools often require you to refresh sheet by sheet, G-Connector allows you to refresh up to 100 sheets simultaneously.
- Write-Back Capabilities: G-Connector’s “write-back” features allow you to edit your Salesforce records directly from Google Sheets and push those changes back to the CRM, effectively using your spreadsheet as a bulk editor.
- Smart Refresh: This feature keeps your sheet updated by refreshing existing rows at their current positions, ensuring that any custom columns or formulas you’ve added next to your Salesforce data remain perfectly aligned.
Together, these features give you the reliability your team needs without the manual copy-paste routine.
Workarounds for Report Exports
While moving to a more robust tool is the best long-term strategy, there are immediate workarounds you can implement to keep your reporting alive during this transition:
- Manage Your Data Volume: To avoid the 3 million record cap per organization per hour (a limit easily reached in large orgs), consider reducing the number of rows per export or staggering your scheduled refreshes across different times of the day.
- The Shift to SOQL: When report exports fail due to the 2,000-row limit or API restrictions, the most effective workaround is often to use Salesforce Object Query Language (SOQL). SOQL is significantly more powerful and flexible than standard reports. While the native Data Connector limits SOQL queries to roughly 10,000 rows, G-Connector’s paid plans allow for much larger exports, helping you bypass the standard report caps entirely. G-Connector includes a nice SOQL statement builder and editor.
- The Report to SOQL Converter: One of the biggest barriers to using SOQL is the learning curve; not every admin wants to write code. Xappex provides a unique, free tool (beta) called the “Report to SOQL converter.” This feature allows you to take an existing Salesforce report and automatically transform it into a SOQL query. This simplifies the transition, giving you the power of a query with the ease of a report-building interface.
Why G-Connector Is the Smarter Salesforce Export Solution
In a modern Salesforce environment, your productivity is only as good as your data access. Relying on a native tool that struggles with MFA enforcement and imposes restrictive row limits is no longer a viable strategy for busy admins.
G-Connector by Xappex offers a seamless, reliable, and enterprise-ready alternative that turns Google Sheets into a functional extension of your CRM. Whether you need to bypass the 2,000-row limit, automate complex snapshots, or easily push data back to Salesforce, G-Connector is the tool that keeps you moving forward.
Try G-Connector for free today and experience reliability, efficiency and the flexibility it brings to your workflows. For Salesforce users who work in Excel, Xappex’s XL-Connector offers similar functionality to G-Connector, letting you sync and edit Salesforce data directly from a spreadsheet. Learn more here.
This post is sponsored by Xappex.
#MFA #SalesforceAdmin #SalesforceDeveloper #Security #Xappex -
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a734f29adb20c14f4081778
Pulse Link: https://otx.alienvault.com/pulse/6a734f29adb20c14f4081778
Pulse Author: CyberHunter_NL
Created: 2026-08-05 14:56:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a734f29adb20c14f4081778
Pulse Link: https://otx.alienvault.com/pulse/6a734f29adb20c14f4081778
Pulse Author: CyberHunter_NL
Created: 2026-08-05 14:56:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/phaas-kits-targeting-us-organizations/
Pulse ID: 6a734121e5564eacc2ad30bc
Pulse Link: https://otx.alienvault.com/pulse/6a734121e5564eacc2ad30bc
Pulse Author: CyberHunter_NL
Created: 2026-08-05 13:56:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/phaas-kits-targeting-us-organizations/
Pulse ID: 6a734121e5564eacc2ad30bc
Pulse Link: https://otx.alienvault.com/pulse/6a734121e5564eacc2ad30bc
Pulse Author: CyberHunter_NL
Created: 2026-08-05 13:56:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a7227e3d5fa0bf81d2044b3
Pulse Link: https://otx.alienvault.com/pulse/6a7227e3d5fa0bf81d2044b3
Pulse Author: CyberHunter_NL
Created: 2026-08-04 17:56:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Indicators extracted from public reporting. Source: https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
Pulse ID: 6a7227e3d5fa0bf81d2044b3
Pulse Link: https://otx.alienvault.com/pulse/6a7227e3d5fa0bf81d2044b3
Pulse Author: CyberHunter_NL
Created: 2026-08-04 17:56:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
Как мы проектировали архитектуру сервиса MFA для миллиона пользователей
Система многофакторной аутентификации находится на критическом участке корпоративной инфраструктуры. Через нее проходят практически все сценарии доступа пользователей: подключение к VPN, вход в виртуальные рабочие столы, корпоративную почту, внутренние веб-приложения, облачные сервисы и административные панели. Если сервис аутентификации становится недоступным, сотрудники не могут начать работу независимо от того, насколько исправно функционируют остальные информационные системы. Поэтому выбор между облачной и локальной моделью эксплуатации в первую очередь определяется не экономикой проекта, а требованиями к доступности, отказоустойчивости, безопасности и соответствию требованиям регуляторов. За последние несколько лет мы реализовали обе модели. MULTIFACTOR используется как классическое on-premise решение внутри инфраструктуры заказчиков и одновременно существует как облачный сервис, который ежедневно обслуживает более миллиона пользователей. За это время стало очевидно, что вопрос «облако или коробка» уже не отражает реальную картину. Гораздо важнее понять, какие требования предъявляются к системе и каким образом должна быть построена ее архитектура.
https://habr.com/ru/companies/multifactor/articles/1065250/
#инфраструктура #архитектура #информационная_безопасность #2fa #mfa #multifactor #мультифактор #мультифакторная_аутентификация #двухфакторная_аутентификация
-
hot take
i fucking HATE multi-factor authentication
it has never done anything except cause me trouble
especially when i accidentally factory reset my phone
it's bullshit. fuck it
-
Také už vás a vaše zákazníky nebaví opisovat kódy do 2fa/mfa aplikací?
Máme pro vás rešení - 2fa aplikace s podporou PUSH notifikací, jednoduše kliknete a je hotovo!Více na https://2fa.adminit.cz
-
Také už vás a vaše zákazníky nebaví opisovat kódy do 2fa/mfa aplikací?
Máme pro vás rešení - 2fa aplikace s podporou PUSH notifikací, jednoduše kliknete a je hotovo!Více na https://2fa.adminit.cz
-
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.
Pulse ID: 6a61c32adbac47eb19574196
Pulse Link: https://otx.alienvault.com/pulse/6a61c32adbac47eb19574196
Pulse Author: AlienVault
Created: 2026-07-23 07:30:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault
-
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.
Pulse ID: 6a61c32adbac47eb19574196
Pulse Link: https://otx.alienvault.com/pulse/6a61c32adbac47eb19574196
Pulse Author: AlienVault
Created: 2026-07-23 07:30:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault
-
A New Name in the Data Extortion Ecosystem?
A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.
Pulse ID: 6a623272a8b581c080b0aee0
Pulse Link: https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0
Pulse Author: AlienVault
Created: 2026-07-23 15:25:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault
-
A New Name in the Data Extortion Ecosystem?
A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.
Pulse ID: 6a623272a8b581c080b0aee0
Pulse Link: https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0
Pulse Author: AlienVault
Created: 2026-07-23 15:25:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault
-
Microsoft 365 : la fin de l’authentification MFA par SMS et appel au profit des passkeys https://www.it-connect.fr/entra-id-fin-authentification-sms-appel-passkeys/ #Microsoft365 #Entreprise #Microsoft #MFA
-
Microsoft 365 : la fin de l’authentification MFA par SMS et appel au profit des passkeys https://www.it-connect.fr/entra-id-fin-authentification-sms-appel-passkeys/ #Microsoft365 #Entreprise #Microsoft #MFA
-
On Moving Past Plotlessness
Author Andrea Uptmor discusses moving past plotlessness after learning to write beautiful sentences in MFA program.
The post On Moving Past Plotlessness appeared first on Writer's Digest.
https://www.writersdigest.com/on-moving-past-plotlessness -
On Moving Past Plotlessness
Author Andrea Uptmor discusses moving past plotlessness after learning to write beautiful sentences in MFA program.
The post On Moving Past Plotlessness appeared first on Writer's Digest.
https://www.writersdigest.com/on-moving-past-plotlessness -
ICYMI: IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. https://ppc.land/ias-study-finds-mfa-traffic-rises-5-on-christmas-eve-and-christmas-day/ #MFA #DigitalMarketing #ChristmasShopping #HolidayMarketing #AdvertisingTrends
-
ICYMI: IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. https://ppc.land/ias-study-finds-mfa-traffic-rises-5-on-christmas-eve-and-christmas-day/ #MFA #DigitalMarketing #ChristmasShopping #HolidayMarketing #AdvertisingTrends
-
Inside a Global Procurement-Themed AiTM Phishing Campaign
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.
Pulse ID: 6a6015d87a94549d768bc929
Pulse Link: https://otx.alienvault.com/pulse/6a6015d87a94549d768bc929
Pulse Author: AlienVault
Created: 2026-07-22 00:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault
-
Inside a Global Procurement-Themed AiTM Phishing Campaign
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.
Pulse ID: 6a6015d87a94549d768bc929
Pulse Link: https://otx.alienvault.com/pulse/6a6015d87a94549d768bc929
Pulse Author: AlienVault
Created: 2026-07-22 00:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault
-
Security Tip: Move to Continuous Authentication. 🛡️ Traditional security validates a user once at login. In a Zero Trust model, identity and device health are verified continuously throughout the session. If a device becomes non-compliant or behavior shifts, access can be revoked instantly. This significantly limits the window for session hijacking and lateral movement. Research the latest vulnerabilities at https://cvedatabase.com #ZeroTrust #InfoSec #CyberSecurity #MFA
-
IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. https://ppc.land/ias-study-finds-mfa-traffic-rises-5-on-christmas-eve-and-christmas-day/ #DigitalMarketing #MFA #TrafficAnalysis #ChristmasMarketing #HolidayBudget
-
IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. https://ppc.land/ias-study-finds-mfa-traffic-rises-5-on-christmas-eve-and-christmas-day/ #DigitalMarketing #MFA #TrafficAnalysis #ChristmasMarketing #HolidayBudget
-
Ein guter Tag
Ich war eben beim Arzt. Ergebnis: Ich bin gesund. Also grob.
Was ich viel cooler fand: Eine der jüngeren MFA fragte mich, was ich denn als Programmierer von KI halten würde. Meine Antwort „Abstand“ machte sie sehr glücklich. Wir sprachen noch ein wenig darüber, wie schlimm das alles im Umfeld geworden ist und dass so viele fälschlicherweise denken, die AI würde ihnen auch nur ansatzweise helfen.
Das Gespräch hat mich sehr glücklich und gleichzeitig zuversichtlich gemacht, dass noch nicht alles verloren ist.
#shortpost #blogpost #blog #AI #Arzt #MFA #WirSindNochNichtKomplettVerloren
-
Ein guter Tag
Ich war eben beim Arzt. Ergebnis: Ich bin gesund. Also grob.
Was ich viel cooler fand: Eine der jüngeren MFA fragte mich, was ich denn als Programmierer von KI halten würde. Meine Antwort „Abstand“ machte sie sehr glücklich. Wir sprachen noch ein wenig darüber, wie schlimm das alles im Umfeld geworden ist und dass so viele fälschlicherweise denken, die AI würde ihnen auch nur ansatzweise helfen.
Das Gespräch hat mich sehr glücklich und gleichzeitig zuversichtlich gemacht, dass noch nicht alles verloren ist.
#shortpost #blogpost #blog #AI #Arzt #MFA #WirSindNochNichtKomplettVerloren
-
Your "secure" MFA push notifications are a backdoor. Attackers spam 30+ prompts at 2AM until you tap Approve. Here's how to stop prompt bombing with number matching and geofencing policies. #Cybersecurity #MFA #ZeroTrust
-
RE: https://mastodon.bsd.cafe/@grahamperrin/116940017144646142
Oracle, you bunch of fucking numpties:
― and your fucking numpty chatbots:
https://www.reddit.com/r/oraclecloud/comments/167e50f/comment/oy98kq8/
-
RE: https://mastodon.bsd.cafe/@grahamperrin/116940017144646142
Oracle, you bunch of fucking numpties:
― and your fucking numpty chatbots:
https://www.reddit.com/r/oraclecloud/comments/167e50f/comment/oy98kq8/
-
Enforce MFA for all accounts—no exceptions. Multi-Factor Authentication drastically reduces account compromise risk and should be mandatory across all identities. Use phish-resistant policy and tokens when possible. Steps: Configure MFA in Entra ID under Security > Authentication Methods, and enforce via Conditional Access policies. Ensure compliance and security best practices #AzureSecurity #ZeroTrust #CyberSecurity #MFA
-
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
Pulse ID: 6a57f26f4f7b83bede7d73d8
Pulse Link: https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8
Pulse Author: AlienVault
Created: 2026-07-15 20:49:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Cloud #CyberSecurity #Email #Google #InfoSec #MFA #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #Telegram #bot #AlienVault
-
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
Pulse ID: 6a57f26f4f7b83bede7d73d8
Pulse Link: https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8
Pulse Author: AlienVault
Created: 2026-07-15 20:49:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Cloud #CyberSecurity #Email #Google #InfoSec #MFA #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #Telegram #bot #AlienVault
-
Website: "We have sent you a code to confirm your identity."
Text: "If anyone asks you for this code, STOP! It's a SCAM! <company> will not ask you for this code."
Website: "So...what's the code?"
-
Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.
Pulse ID: 6a56e4f5789e1bf3de8e82be
Pulse Link: https://otx.alienvault.com/pulse/6a56e4f5789e1bf3de8e82be
Pulse Author: AlienVault
Created: 2026-07-15 01:40:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault
-
Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge
Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.
Pulse ID: 6a56e4f5789e1bf3de8e82be
Pulse Link: https://otx.alienvault.com/pulse/6a56e4f5789e1bf3de8e82be
Pulse Author: AlienVault
Created: 2026-07-15 01:40:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault
-
redb.Identity: OAuth 2.1 / OpenID сервер на .NET, где протокол отделён от транспорта, по шине или вообще без сети
Есть три привычных способа сделать OAuth/OIDC в .NET, и каждый чем-то неудобен. Первый — ASP.NET -привязанные решения (Duende IdentityServer, ASP.NET Identity, сэмплы OpenIddict). Мощно, но каждый эндпоинт — это HTTP-middleware. Захотелось дёрнуть token из воркера или из консьюмера шины? Поднимай HTTP-листенер и ходи через loopback. Хочешь протестировать конвейер выдачи токена в изоляции? Готовь WebApplicationFactory . Второй — готовые IAM-платформы (Keycloak, Auth0, Okta). Богато по фичам, но это отдельный сервис со своим рантаймом, своей админкой, своей базой, своей моделью конфигурации и своим деплоем. Мультиарендно — да, встраиваемо — нет. Третий — написать своё . И в третий раз за десятилетие переизобрести Code+PKCE, ротацию refresh-токенов, хранение согласий, отзыв сессий, защиту от replay в MFA, ротацию JWKS, шаринг ключей между репликами и backchannel-logout по RFC 8417.
https://habr.com/ru/articles/1058700/
#OAuth_21 #OpenID_Connect #identity_server #аутентификация #SSO #OpenIddict #NET #C# #SCIM #MFA
-
Why Passwords Alone Are No Longer Enough in 2026
Why Passwords Alone Are No Longer Enough in 2026 Meta Description: Learn why passwords alone are no longer enough in 2026 and discover how multi-factor authentication, passkeys, and better security habits can protect your online accounts. Every day, billions of people use passwords to access email accounts, social media, banking apps, and online services. For years, passwords have been the first line of defense against cybercriminals. However, in 2026, cybersecurity experts agree that […]https://raytechgh.wordpress.com/2026/07/13/why-passwords-alone-are-no-longer-enough-in-2026/
-
Why Passwords Alone Are No Longer Enough in 2026
Why Passwords Alone Are No Longer Enough in 2026 Meta Description: Learn why passwords alone are no longer enough in 2026 and discover how multi-factor authentication, passkeys, and better security habits can protect your online accounts. Every day, billions of people use passwords to access email accounts, social media, banking apps, and online services. For years, passwords have been the first line of defense against cybercriminals. However, in 2026, cybersecurity experts agree that […]https://raytechgh.wordpress.com/2026/07/13/why-passwords-alone-are-no-longer-enough-in-2026/