home.social

#mfa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mfa, aggregated by home.social.

fetched live
  1. This #Yubico #YubiKey Standard from approximately 2012 was on my personal key ring ever since on a daily basis. It has been my first FIDO2 token.

    It now ceased to work after approx. 14 years as it's no longer recognized by a computer when plugged in.

    Fortunately, it's been mostly replaced by a newer key months ago. So no data loss. Furthermore, I always had a second token that was registered with the same services anyway.

    That's my personal data point for durability of #FIDO2 #security hardware tokens. Not bad, I'd say. 👍️

    I still prefer FIDO2 HW tokens over #passkeys because HW tokens are not prone to #phishing: karl-voit.at/FIDO2-vs-Passkeys/ (German)

    #2FA #MFA #securitytokens #publicvoit #20241005_FIDO2VsPasskeys

  2. This #Yubico #YubiKey Standard from approximately 2012 was on my personal key ring ever since on a daily basis. It has been my first FIDO2 token.

    It now ceased to work after approx. 14 years as it's no longer recognized by a computer when plugged in.

    Fortunately, it's been mostly replaced by a newer key months ago. So no data loss. Furthermore, I always had a second token that was registered with the same services anyway.

    That's my personal data point for durability of #FIDO2 #security hardware tokens. Not bad, I'd say. 👍️

    I still prefer FIDO2 HW tokens over #passkeys because HW tokens are not prone to #phishing: karl-voit.at/FIDO2-vs-Passkeys/ (German)

    #2FA #MFA #securitytokens #publicvoit #20241005_FIDO2VsPasskeys

  3. 📰 Cisco Talos uncovers 'JWR' phishing framework with live operator steering

    Cisco Talos uncovers 'JWR,' a sophisticated phishing framework with live operators who steal credentials, 2FA codes, and IDs in real-time. The framework uses encrypted WebSockets to bypass MFA. #Phishing #CyberSecurity #InfoSec #MFA

    🔗 cyber.netsecops.io/articles/ci

  4. Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA

    Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.

    Pulse ID: 6a7b418c9c13f8e6bf2c89c7
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: cryptocti
    Created: 2026-08-11 15:36:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti

  5. Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA

    Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.

    Pulse ID: 6a7b418c9c13f8e6bf2c89c7
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: cryptocti
    Created: 2026-08-11 15:36:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti

  6. Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA

    The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
    and device-code phishing to steal Microsoft 365 authentication tokens and
    bypass MFA. Active campaigns exploit trusted sender configurations and
    phishing lures to compromise accounts. Stolen tokens enable attackers to
    access Outlook, Teams, SharePoint and OneDrive while evading
    conventional authentication-based security controls.

    Pulse ID: 6a79bef48cee5cb15fd34fd2
    Pulse Link: otx.alienvault.com/pulse/6a79b
    Pulse Author: cryptocti
    Created: 2026-08-10 12:07:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti

  7. Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA

    The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
    and device-code phishing to steal Microsoft 365 authentication tokens and
    bypass MFA. Active campaigns exploit trusted sender configurations and
    phishing lures to compromise accounts. Stolen tokens enable attackers to
    access Outlook, Teams, SharePoint and OneDrive while evading
    conventional authentication-based security controls.

    Pulse ID: 6a79bef48cee5cb15fd34fd2
    Pulse Link: otx.alienvault.com/pulse/6a79b
    Pulse Author: cryptocti
    Created: 2026-08-10 12:07:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti

  8. 📰 Attacker Pleads Guilty in Massive 2024 Snowflake Breach Campaign

    Justice served: The primary attacker behind the massive 2024 Snowflake customer data breaches has pleaded guilty. The campaign exploited stolen credentials on accounts without MFA, exposing 100M+ records. #Snowflake #DataBreach #CyberSecurity #MFA

    🔗 cyber.netsecops.io/articles/at

  9. Why Your Salesforce Report Exports Are Failing and How to Fix It

    If you are a sales or support operations expert on Salesforce, you most likely use the export feature under reports. When you want to do your own analysis and follow up on MS Excel or Google Sheets, or send the list to an external provider this feature comes to the rescue. Older Orgs have many periodic workflows executed by a variety of users that involve such steps.

    If you have been following Salesforce Break, you know that there have been many security incidents involving Salesforce recently. When Salesforce rolled out the recent tightened security measures, many of these report export workflows started breaking down. Salesforce now requires a step-up authentication whenever a user wants to export or print report data.

    If you have been using an AppExchange (now AgentExchange) App for your data exports, the chances are that they broke down as well. 

    If your App or integration provider keeps up with these recent requirements and turns them into updates, then you are in luck. There are still supported and secure ways of exporting your data out of Salesforce.

    The Problem with the Native Salesforce Data Connector

    Several major issues make the native connector difficult to use in a professional environment:

    1. Authentication Hurdles

    Step-Up Authentication often triggers when a user attempts to export reports, leading to constant re-authentication requests. Salesforce says API access should not initiate step-up requests, but the migration to tightened security measures has been very painful and inconsistent. For automated or scheduled sheets, the sync is likely to fail because the background process cannot satisfy the interactive MFA challenge.

    2. Analytics API Limitations

    Salesforce has moved toward the Analytics API as the primary data extraction method for many integrated apps. While modern, this API brings strict limitations that were less prominent in older methods. Most notably, users are often hitting a 2,000-row limit on report exports through this method. In an era of “Big Data,” a 2,000-row cap is an immediate dealbreaker for most financial, sales, or operational audits. There is also an Org-wide limit that amounts to about 3 million records capacity per hour. This number, while it sounds pretty large, can be reached very easily in large orgs.

    3. Changing Security Landscape

    Beyond the hard caps, reliability has become a major concern. Recent data breach incidents forced Salesforce to make quick changes out of their usual release cycles. These changes broke workflows and decreased the reliability of solutions that have been working for years. If you are an admin of a Salesforce Org, it may be a good idea to trust a reliable partner to keep up with these changes and adopt to the new secured architecture as the requirements change.

    The Solution: G-Connector by Xappex

    Here is how I used the G-Connector by Xappex:

    Use case: Bring in a report to Google sheets and prepare a workflow that can manage high volume of records.

    Install the G-Connector Salesforce Sync Google Sheet Extension

    Installing the G-Connector Google extension is fairly easy. You go to this link and install the extension by logging in with your Google Workspace username and password. You need to make sure that your Salesforce user is API-enabled. Once you authenticate, you go to the Salesforce Connected Apps OAuth Usage screen and install the Xappex connected app. This step should ensure that the connection can be established without issues in the future. Note that Xappex needs a few permissions, and these permissions will be listed for you to approve on both sides (Google and Salesforce).

    Import Data (Or Export Data)

    Import or export: it depends on where you’re standing, I guess. You’ll see these terms used interchangeably throughout the post.

    Once you establish the org connection, go to Import Data / New from Report on the Xappex G-Connector extension. Choose the report you want to import from the pulldown showing all Salesforce reports. You can import all detail rows unformatted, or import the formatted report.

    Future-Proof Your Workflow For Larger Volumes

    The import went through without issues, but you are not sure what will happen when all users ask for report data in the future and/or the record count grows. To future proof your workflow, you can convert your report to SOQL and have Xappex pull the same data using the Salesforce API without involving reports. This feature, while still in beta, actually works very well. Click on the SOQL converter and generate the SOQL statement for your report.

    Your workflow will not be subject to rate limits for the Analytics API now.

    What does the Xappex G-Connector solution provide?

    If you find yourself manually copying and pasting data to bypass the recently-added road blocks, it’s time to consider an enterprise-grade alternative. G-Connector by Xappex was designed to solve the exact pain points that the native connector can not cope with.

    As a robust, professional-tier integration, G-Connector offers several advantages:

    • Solid Reliability: Xappex actively maintains G-Connector to stay ahead of Salesforce’s updates, including MFA and authentication changes, ensuring your data flows without interruption.
    • High Efficiency: While native tools often require you to refresh sheet by sheet, G-Connector allows you to refresh up to 100 sheets simultaneously.
    • Write-Back Capabilities: G-Connector’s “write-back” features allow you to edit your Salesforce records directly from Google Sheets and push those changes back to the CRM, effectively using your spreadsheet as a bulk editor.
    • Smart Refresh: This feature keeps your sheet updated by refreshing existing rows at their current positions, ensuring that any custom columns or formulas you’ve added next to your Salesforce data remain perfectly aligned.

    Together, these features give you the reliability your team needs without the manual copy-paste routine.

    Workarounds for Report Exports

    While moving to a more robust tool is the best long-term strategy, there are immediate workarounds you can implement to keep your reporting alive during this transition:

    • Manage Your Data Volume: To avoid the 3 million record cap per organization per hour (a limit easily reached in large orgs), consider reducing the number of rows per export or staggering your scheduled refreshes across different times of the day.
    • The Shift to SOQL: When report exports fail due to the 2,000-row limit or API restrictions, the most effective workaround is often to use Salesforce Object Query Language (SOQL). SOQL is significantly more powerful and flexible than standard reports. While the native Data Connector limits SOQL queries to roughly 10,000 rows, G-Connector’s paid plans allow for much larger exports, helping you bypass the standard report caps entirely. G-Connector includes a nice SOQL statement builder and editor.

    • The Report to SOQL Converter: One of the biggest barriers to using SOQL is the learning curve; not every admin wants to write code. Xappex provides a unique, free tool (beta) called the “Report to SOQL converter.” This feature allows you to take an existing Salesforce report and automatically transform it into a SOQL query. This simplifies the transition, giving you the power of a query with the ease of a report-building interface.

    Why G-Connector Is the Smarter Salesforce Export Solution

    In a modern Salesforce environment, your productivity is only as good as your data access. Relying on a native tool that struggles with MFA enforcement and imposes restrictive row limits is no longer a viable strategy for busy admins.

    G-Connector by Xappex offers a seamless, reliable, and enterprise-ready alternative that turns Google Sheets into a functional extension of your CRM. Whether you need to bypass the 2,000-row limit, automate complex snapshots, or easily push data back to Salesforce, G-Connector is the tool that keeps you moving forward.

    Try G-Connector for free today and experience reliability, efficiency and the flexibility it brings to your workflows. For Salesforce users who work in Excel, Xappex’s XL-Connector offers similar functionality to G-Connector, letting you sync and edit Salesforce data directly from a spreadsheet. Learn more here.

    This post is sponsored by Xappex.

    #MFA #SalesforceAdmin #SalesforceDeveloper #Security #Xappex
  10. Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a734f29adb20c14f4081778
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 14:56:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  11. Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a734f29adb20c14f4081778
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 14:56:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #Email #HTTP #HTTPS #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  12. Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

    Indicators extracted from public reporting. Source: cybersecuritynews.com/phaas-ki

    Pulse ID: 6a734121e5564eacc2ad30bc
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 13:56:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  13. Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

    Indicators extracted from public reporting. Source: cybersecuritynews.com/phaas-ki

    Pulse ID: 6a734121e5564eacc2ad30bc
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 13:56:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  14. Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a7227e3d5fa0bf81d2044b3
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 17:56:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  15. Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    Indicators extracted from public reporting. Source: zerobec.com/blog/greatness-pha

    Pulse ID: 6a7227e3d5fa0bf81d2044b3
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 17:56:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  16. How legitimate cloud platforms enable phishers to bypass MFA

    Indicators extracted from public reporting. Source: securelist.com/cloud-platforms

    Pulse ID: 6a71e195cc4d01c3cb1caa89
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 12:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL

  17. How legitimate cloud platforms enable phishers to bypass MFA

    Indicators extracted from public reporting. Source: securelist.com/cloud-platforms

    Pulse ID: 6a71e195cc4d01c3cb1caa89
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 12:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL

  18. Как мы проектировали архитектуру сервиса MFA для миллиона пользователей

    Система многофакторной аутентификации находится на критическом участке корпоративной инфраструктуры. Через нее проходят практически все сценарии доступа пользователей: подключение к VPN, вход в виртуальные рабочие столы, корпоративную почту, внутренние веб-приложения, облачные сервисы и административные панели. Если сервис аутентификации становится недоступным, сотрудники не могут начать работу независимо от того, насколько исправно функционируют остальные информационные системы. Поэтому выбор между облачной и локальной моделью эксплуатации в первую очередь определяется не экономикой проекта, а требованиями к доступности, отказоустойчивости, безопасности и соответствию требованиям регуляторов. За последние несколько лет мы реализовали обе модели. MULTIFACTOR используется как классическое on-premise решение внутри инфраструктуры заказчиков и одновременно существует как облачный сервис, который ежедневно обслуживает более миллиона пользователей. За это время стало очевидно, что вопрос «облако или коробка» уже не отражает реальную картину. Гораздо важнее понять, какие требования предъявляются к системе и каким образом должна быть построена ее архитектура.

    habr.com/ru/companies/multifac

    #инфраструктура #архитектура #информационная_безопасность #2fa #mfa #multifactor #мультифактор #мультифакторная_аутентификация #двухфакторная_аутентификация

  19. hot take

    i fucking HATE multi-factor authentication

    it has never done anything except cause me trouble

    especially when i accidentally factory reset my phone

    it's bullshit. fuck it

    #MFA #2FA

  20. Také už vás a vaše zákazníky nebaví opisovat kódy do 2fa/mfa aplikací?
    Máme pro vás rešení - 2fa aplikace s podporou PUSH notifikací, jednoduše kliknete a je hotovo!

    Více na 2fa.adminit.cz

    #it #2fa #mfa #bezpecnost #adminitsro

  21. Také už vás a vaše zákazníky nebaví opisovat kódy do 2fa/mfa aplikací?
    Máme pro vás rešení - 2fa aplikace s podporou PUSH notifikací, jednoduše kliknete a je hotovo!

    Více na 2fa.adminit.cz

    #it #2fa #mfa #bezpecnost #adminitsro

  22. Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

    Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.

    Pulse ID: 6a61c32adbac47eb19574196
    Pulse Link: otx.alienvault.com/pulse/6a61c
    Pulse Author: AlienVault
    Created: 2026-07-23 07:30:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault

  23. Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

    Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.

    Pulse ID: 6a61c32adbac47eb19574196
    Pulse Link: otx.alienvault.com/pulse/6a61c
    Pulse Author: AlienVault
    Created: 2026-07-23 07:30:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault

  24. A New Name in the Data Extortion Ecosystem?

    A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

    Pulse ID: 6a623272a8b581c080b0aee0
    Pulse Link: otx.alienvault.com/pulse/6a623
    Pulse Author: AlienVault
    Created: 2026-07-23 15:25:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault

  25. A New Name in the Data Extortion Ecosystem?

    A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

    Pulse ID: 6a623272a8b581c080b0aee0
    Pulse Link: otx.alienvault.com/pulse/6a623
    Pulse Author: AlienVault
    Created: 2026-07-23 15:25:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault

  26. On Moving Past Plotlessness

    Author Andrea Uptmor discusses moving past plotlessness after learning to write beautiful sentences in MFA program.
    The post On Moving Past Plotlessness appeared first on Writer's Digest.
    writersdigest.com/on-moving-pa

    #Plot #WriteBetterFiction #MFA #plot #plotdevelopment

  27. On Moving Past Plotlessness

    Author Andrea Uptmor discusses moving past plotlessness after learning to write beautiful sentences in MFA program.
    The post On Moving Past Plotlessness appeared first on Writer's Digest.
    writersdigest.com/on-moving-pa

    #Plot #WriteBetterFiction #MFA #plot #plotdevelopment

  28. ICYMI: IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. ppc.land/ias-study-finds-mfa-t #MFA #DigitalMarketing #ChristmasShopping #HolidayMarketing #AdvertisingTrends

  29. ICYMI: IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. ppc.land/ias-study-finds-mfa-t #MFA #DigitalMarketing #ChristmasShopping #HolidayMarketing #AdvertisingTrends

  30. Inside a Global Procurement-Themed AiTM Phishing Campaign

    A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

    Pulse ID: 6a6015d87a94549d768bc929
    Pulse Link: otx.alienvault.com/pulse/6a601
    Pulse Author: AlienVault
    Created: 2026-07-22 00:59:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault

  31. Inside a Global Procurement-Themed AiTM Phishing Campaign

    A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

    Pulse ID: 6a6015d87a94549d768bc929
    Pulse Link: otx.alienvault.com/pulse/6a601
    Pulse Author: AlienVault
    Created: 2026-07-22 00:59:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault

  32. Security Tip: Move to Continuous Authentication. 🛡️ Traditional security validates a user once at login. In a Zero Trust model, identity and device health are verified continuously throughout the session. If a device becomes non-compliant or behavior shifts, access can be revoked instantly. This significantly limits the window for session hijacking and lateral movement. Research the latest vulnerabilities at cvedatabase.com

  33. IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. ppc.land/ias-study-finds-mfa-t #DigitalMarketing #MFA #TrafficAnalysis #ChristmasMarketing #HolidayBudget

  34. IAS study finds MFA traffic rises 5% on Christmas Eve and Christmas Day: Impressions surge 280% during peak shopping weeks, yet made-for-advertising traffic expands 5% over Christmas, pressuring where marketers place holiday budgets. ppc.land/ias-study-finds-mfa-t #DigitalMarketing #MFA #TrafficAnalysis #ChristmasMarketing #HolidayBudget

  35. Ein guter Tag

    Ich war eben beim Arzt. Ergebnis: Ich bin gesund. Also grob.

    Was ich viel cooler fand: Eine der jüngeren MFA fragte mich, was ich denn als Programmierer von KI halten würde. Meine Antwort „Abstand“ machte sie sehr glücklich. Wir sprachen noch ein wenig darüber, wie schlimm das alles im Umfeld geworden ist und dass so viele fälschlicherweise denken, die AI würde ihnen auch nur ansatzweise helfen.

    Das Gespräch hat mich sehr glücklich und gleichzeitig zuversichtlich gemacht, dass noch nicht alles verloren ist.

    🔗

    #shortpost #blogpost #blog #AI #Arzt #MFA #WirSindNochNichtKomplettVerloren

  36. Ein guter Tag

    Ich war eben beim Arzt. Ergebnis: Ich bin gesund. Also grob.

    Was ich viel cooler fand: Eine der jüngeren MFA fragte mich, was ich denn als Programmierer von KI halten würde. Meine Antwort „Abstand“ machte sie sehr glücklich. Wir sprachen noch ein wenig darüber, wie schlimm das alles im Umfeld geworden ist und dass so viele fälschlicherweise denken, die AI würde ihnen auch nur ansatzweise helfen.

    Das Gespräch hat mich sehr glücklich und gleichzeitig zuversichtlich gemacht, dass noch nicht alles verloren ist.

    🔗

    #shortpost #blogpost #blog #AI #Arzt #MFA #WirSindNochNichtKomplettVerloren

  37. @Remedios_Varo_Bot

    This piece is on display at the #MFA (Museum of Fine Arts) in #Boston (or at least it was a few weeks ago, and I'm pretty sure it's part of the permanent collection).

    It was my entry into Varo fandom, and I highly recommend it.

  38. @Remedios_Varo_Bot

    This piece is on display at the #MFA (Museum of Fine Arts) in #Boston (or at least it was a few weeks ago, and I'm pretty sure it's part of the permanent collection).

    It was my entry into Varo fandom, and I highly recommend it.

  39. Your "secure" MFA push notifications are a backdoor. Attackers spam 30+ prompts at 2AM until you tap Approve. Here's how to stop prompt bombing with number matching and geofencing policies. #Cybersecurity #MFA #ZeroTrust

    valtersit.com/guides/security/

  40. Enforce MFA for all accounts—no exceptions. Multi-Factor Authentication drastically reduces account compromise risk and should be mandatory across all identities. Use phish-resistant policy and tokens when possible. Steps: Configure MFA in Entra ID under Security > Authentication Methods, and enforce via Conditional Access policies. Ensure compliance and security best practices

  41. redb.Identity: OAuth 2.1 / OpenID сервер на .NET, где протокол отделён от транспорта, по шине или вообще без сети

    Есть три привычных способа сделать OAuth/OIDC в .NET, и каждый чем-то неудобен. Первый — ASP.NET -привязанные решения (Duende IdentityServer, ASP.NET Identity, сэмплы OpenIddict). Мощно, но каждый эндпоинт — это HTTP-middleware. Захотелось дёрнуть token из воркера или из консьюмера шины? Поднимай HTTP-листенер и ходи через loopback. Хочешь протестировать конвейер выдачи токена в изоляции? Готовь WebApplicationFactory . Второй — готовые IAM-платформы (Keycloak, Auth0, Okta). Богато по фичам, но это отдельный сервис со своим рантаймом, своей админкой, своей базой, своей моделью конфигурации и своим деплоем. Мультиарендно — да, встраиваемо — нет. Третий — написать своё . И в третий раз за десятилетие переизобрести Code+PKCE, ротацию refresh-токенов, хранение согласий, отзыв сессий, защиту от replay в MFA, ротацию JWKS, шаринг ключей между репликами и backchannel-logout по RFC 8417.

    habr.com/ru/articles/1058700/

    #OAuth_21 #OpenID_Connect #identity_server #аутентификация #SSO #OpenIddict #NET #C# #SCIM #MFA

  42. Why Passwords Alone Are No Longer Enough in 2026

    Why Passwords Alone Are No Longer Enough in 2026 Meta Description: Learn why passwords alone are no longer enough in 2026 and discover how multi-factor authentication, passkeys, and better security habits can protect your online accounts. Every day, billions of people use passwords to access email accounts, social media, banking apps, and online services. For years, passwords have been the first line of defense against cybercriminals. However, in 2026, cybersecurity experts agree that […]

    raytechgh.wordpress.com/2026/0

  43. Why Passwords Alone Are No Longer Enough in 2026

    Why Passwords Alone Are No Longer Enough in 2026 Meta Description: Learn why passwords alone are no longer enough in 2026 and discover how multi-factor authentication, passkeys, and better security habits can protect your online accounts. Every day, billions of people use passwords to access email accounts, social media, banking apps, and online services. For years, passwords have been the first line of defense against cybercriminals. However, in 2026, cybersecurity experts agree that […]

    raytechgh.wordpress.com/2026/0

  44. FYI: Advertisers face 4 times higher MFA rate on mobile web display, IAS finds: Mobile web held 45.1% of open web impressions but drew 71.5% of ad clutter and 54.9% of suitability failures in 2025, showing where 2026 controls tighten next. ppc.land/advertisers-face-4-ti #Advertising #MobileMarketing #DigitalAdvertising #AdTech #MFA

  45. This is the warning message I get for the MFA 2FA multi-factor authentication parameters for the freeBSD forum.

    Is there anyone here who can tell me where I can post this so that they can look into the issue?

    @stefano

    Please boost for visibility

    #freeBSD #BSD #MFA #2FA #InfoSec #weak #cryptography #cipher #programming #OpenSource #forum