Security news aggregator

Latest coverage for MFA

Stay secure with MFA updates: Explore the latest in multi-factor authentication trends, news, and best practices to safeguard your digital assets.

474 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

MFA, or Multi-Factor Authentication, is a security mechanism that requires users to provide two or more verification factors to gain access to a resource such as an application, online account, or a VPN. Unlike traditional single-factor authentication, which uses only a username and password, MFA adds additional layers of security, making it significantly more difficult for unauthorized individuals to breach accounts or systems.

In the context of information security, MFA is a crucial tool that helps protect both user identities and sensitive data. It operates on the principle that even if one authentication factor is compromised, unauthorized users would still need to bypass additional barriers. These factors typically fall into three categories: something you know (like a password), something you have (like a smartphone or a hardware token), and something you are (biometric data such as fingerprints or facial recognition).

The effective implementation of MFA can drastically reduce the risk of cyber attacks such as phishing, brute force, and keylogger attempts, by ensuring that only authenticated users with the necessary credentials can access secure environments.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 474 Filtered view
Bank Info Security 6 days, 2 hours ago

Breach Roundup: US Troops Tracked With Cell Phone Data

Also, Kali365 Bypasses MFA, Silent Ransom Group Makes Office CallsThis week, active duty troops tracked, Kali365 bypassed MFA, Australian lawmakers phished on WhatsApp, Silent Ransom escalated IT scams, Lithuania and German hospitals disclosed breaches, pro-Russian infrastructure providers arrested, CISA warned of active LiteSpeed exploitation.

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now - meanwhile some researcher casually drops a technique that turns a "minor" foothold into total account

Fraudsters Tokenize Stolen Cards Into Attacker WalletsGoogle Threat Intelligence Group warned that Chinese-language phishing-as-a-service platforms are using AI, encrypted messaging and real-time OTP interception to bypass multifactor authentication and provision stolen payment cards into attacker-controlled digital wallets worldwide.

Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they don't need to steal the second factor: they just need the user to hand it over

Bank Info Security 1 week, 6 days ago

Breach Roundup: Shai-Hulud Copycat Hits npm

Also, YellowKey Gets CVE, 7-Eleven Breach, Linux Maintainers Warn on AI Bug SpamThis week, more incidents than we can list here. Among them: cloned Shai-Hulud malware, a new maximum CVSS Cisco flaw. Edge to stop loading passwords in plaintext. Tycoon 2FA offers a way around Microsoft multifactor. Convenience, taquitos and data breach: The 7-Eleven story. A MENA crackdown.

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a

Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation

Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter controls don't see it. Your MFA doesn't stop it. And when an attacker gets hold of one, they don't need a password

Bank Info Security 1 month, 2 weeks ago

Defending Identity in the Age of AI Attacks

Why CISOs Must Rethink Trust, MFA and Machine Identity GovernanceAI-driven phishing emails, voice deepfakes and synthetic identities have changed the threat landscape. Attackers now mimic trusted users with precision. Security teams can no longer rely on static controls or traditional verification methods.

Loading more headlines...