Latest updates for Multi-Factor Authentication (Mfa)
Fresh curated links around Multi-Factor Authentication (MFA) are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
- Two Factor Authentication (2FA)
- How Your Multi-factor Authentication (MFA) May Be Compromised
- MFA used to be a nice-to-have. Now insurers just say no without it
Post angles to try
Fresh articles and ideas
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
How Your Multi-factor Authentication (MFA) May Be Compromised
Learn how your business' multi-factor authentication (MFA) may be compromised, and what you can do to to keep protecting your data.
MFA used to be a nice-to-have. Now insurers just say no without it
"Now it's probably an outright no": how multi-factor authentication went from negotiable to non-negotiable
When MFA isn’t enough: The session hijacking problem
Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of tha...
Why MFA fatigue attacks keep working
MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—j...
New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code ph...
Microsoft Authenticator - Microsoft Corporation
Use Microsoft Authenticator for easy, secure sign-ins for all your online accounts using multi-factor authentication, passwordless, or password autofill. You also have additional a...
What Is Two-Factor Authentication and Which Type Is Safest?
Two-factor authentication (2FA) adds a vital secondary check so a stolen password alone cannot compromise your account, but protection levels vary significantly by method. The safe...
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing at...
Replace Remember MFA with Conditional Access Sign-in Frequency in Microsoft 365
While legacy remember MFA feature reduced MFA prompts on trusted devices, Microsoft now recommends using Conditional Access sign-in frequency to manage user reauthentication in Mic...
Microsoft Makes Passkeys Default in Entra ID, Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice multifactor authenticatio...
Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts
Hackers are pairing AI-generated phone calls with fake banking pages to take over customer accounts, even when multi-factor authentication is enabled. The campaign, tracked as Balo...
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber th...
New Bluekit Phishing-as-a-Service Bypasses MFA to Steal Microsoft Login Credentials
A sophisticated Phishing-as-a-Service (PhaaS) platform called Bluekit has been confirmed operational at scale, with cybersecurity firm Netcraft detecting approximately 70 live host...
Step‑Up Authentication vs 2FA: зачем нужен второй фактор внутри активной сессии
Двухфакторная аутентификация давно стала стандартом защиты корпоративных систем. Но для работы с персональными данными и другими критичными операциями проверки только при входе в с...
New Phishing Kits Use Open-Source Tools to Bypass MFA
Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle...
Microsoft Makes Passkeys Default: What Identity And Security Leaders Need To Do
Microsoft’s July 2026 announcement that passkeys will become the default authentication method for all users in Microsoft Entra ID is a clear inflection point for phishing-resistan...
Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users t...
Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments
A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass...
Security boss thought MFA would be too much security
One rule for the workers, another for execs
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
UNC1151 tracked by many as Ghostwriter or FrostyNeighbor has advanced a credential-phishing technique that uses a real-time WebSocket relay to defeat SMS and OTP-based multi-factor...
Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also r...
Cómo Las Contraseñas Seguras Y La Autenticación Multifactor Mejoran La Seguridad En Línea
Todos los días abrimos decenas de cuentas: el correo, el banco, las redes sociales, alguna app de compras. Pocas veces nos detenemos a pensar qué tan fácil sería para alguien entra...
Turn fresh research into a full content calendar
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.