search
multi-factor authentication
Trends
- 1Trump Mobile data breach exposes 3,615 customers●Trump Mobile data breach: BYOD leaks Trump Mobile customer data for 3,615 people, including Trump allies, via an infoste
A data breach at Trump Mobile has exposed personal information for 3,615 customers, reportedly including allies of Donald Trump. The leak stems from a bring-your-own-device setup compromised by an infostealer, with the account lacking multi-factor authentication. Security outlets are highlighting the incident as an example of how BYOD policies and missing MFA leave sensitive customer data open to theft.
- 2Hotels Urged to Strengthen Defenses Against Password Attacks▼How Hotels Can Prevent Password Attacks and Protect Guest Information |
Hotel Technology News reports that hotels face growing risk from password attacks that can expose guest information such as payment details and identity records. The piece outlines steps hospitality operators can take, including stronger password policies, multi-factor authentication and staff training, to protect guest data and avoid breaches that damage reputation and trigger regulatory penalties.
- 3Fake ChatGPT and Gemini sites phish ad accounts●Fake ChatGPT, Gemini sites phish ad accounts and MFA codes https:// fawkes.rocks/2026/10/06/fake-c hatgpt-gemini-sites-p
Security researchers are warning about fraudulent websites imitating ChatGPT and Gemini that trick users into handing over advertising account credentials and multi-factor authentication codes. The fake AI tool pages are used to harvest logins, potentially giving attackers control of victims' ad accounts and bypassing two-factor security. Users are being urged to verify URLs and treat unsolicited AI tool links with caution.
- 4Fake ChatGPT and Gemini sites steal ad accounts and MFA codes●Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes https://www. bleepingcomputer.com/news/secu rity/fake-c
Fraudulent websites impersonating ChatGPT and Gemini are tricking users into handing over advertising account credentials and multi-factor authentication codes, according to a report by BleepingComputer. The fake AI sites harvest logins used for Google and Microsoft advertising platforms, potentially letting attackers hijack ad accounts and run costly fraudulent campaigns. Security researchers are warning businesses to verify URLs before signing in.
- 5Keycloak flaw lets stolen passwords bypass mandatory MFA●CVE-2026-105305 affects Red Hat build of Keycloak. The OIDC Device Authorization Grant flow does not enforce a client's
A vulnerability tracked as CVE-2026-105305 affects the Red Hat build of Keycloak. The OIDC Device Authorization Grant flow fails to enforce a client's minimum authentication level, meaning a stolen password could bypass mandatory multi-factor authentication and gain access to the Admin REST API. No exploitation has been confirmed, and Red Hat has a fix available. Security practitioners are sharing the advisory and urging admins to patch promptly.
- 6Small business cybersecurity: low-cost basics that stop most attacks●Small business cybersecurity: The low-cost basics that stop most attacks
Guidance is circulating on affordable cybersecurity fundamentals for small businesses, arguing that basic low-cost measures — such as strong passwords, multi-factor authentication, software updates and staff awareness — can prevent the majority of common attacks. Small firms are often targeted because they lack dedicated security teams, and owners are being encouraged to prioritise these simple defenses over expensive solutions.
- 7Workers increasingly forced to use personal phones for work MFA●I don’t know when we crossed into this weird world of “you WILL use your personal mobile device to do MFA and we will NO
A cybersecurity worker is voicing frustration that many employers now require staff to install multi-factor authentication apps on their personal mobile phones without reimbursing the cost, with the complaint striking a chord among people in tech and security circles. The broader debate centres on whether companies should provide dedicated devices or compensate employees when personal hardware is effectively commandeered for workplace security.
- 8Swiss government login AGOV allows multi-factor account sharing●MFA und Account Sharing schlossen sich bis jetzt aus, das Schweizer Behörden Login # AGOV ermöglicht nun genau das 😱 htt
The Swiss authorities' login system AGOV now offers a shared-use feature, allowing several people to use the same account even when multi-factor authentication is enabled. Commenters in the cybersecurity community have reacted with alarm, pointing out that MFA and account sharing have traditionally been considered mutually exclusive, and questioning how the feature affects accountability and security for government services.
- 9Simple settings changes could protect you from AI hackers●Simple settings changes that could protect you from AI hackers
Scammers are increasingly using artificial intelligence to craft convincing phishing messages, voice clones and fake identities, and security reporters are urging people to act. Practical steps being highlighted include turning on multi-factor authentication, tightening privacy settings, limiting what personal information is publicly visible, and being skeptical of urgent requests, even when they appear to come from someone you know.
- 10Experts question whether web authentication is sustainable▼Does anyone else get the feeling that the way the world authenticates to thousands of services on the Web, and the curre
A cybersecurity commentator is asking whether the way the world authenticates to thousands of online services is sustainable, arguing that current login systems outpace the technical literacy of users across generations. The remark has struck a chord among information security professionals, who regularly point to passwords, phishing, and inconsistent security standards as growing problems. It feeds into a wider debate over passkeys, multi-factor authentication, and how to design account security that ordinary people can actually manage.
- 11Hundreds of Wisconsin jurisdictions skipping cybersecurity best practices▼Hundreds of Wisconsin jurisdictions not using cybersecurity best practices
Hundreds of local election jurisdictions across Wisconsin are not following recommended cybersecurity best practices, according to reporting by Votebeat. The finding raises questions about the security of election infrastructure in the state ahead of upcoming votes, as experts urge local clerks to adopt stronger protections such as multi-factor authentication and regular security audits.
- 12US Department of War promotes 'Brilliant at the Basics' for Cybersecurity Awareness Month▼Department of War Champions 'Brilliant at the Basics' for Cybersecurity Awareness Month
The US Department of War is marking Cybersecurity Awareness Month by promoting its 'Brilliant at the Basics' campaign, urging staff and the wider public to follow fundamental cyber hygiene such as strong passwords, phishing awareness and multi-factor authentication. The initiative highlights how basic defensive practices remain the department's core message against growing digital threats.
- 13MFA's False Sense of Security: The Identity Trap●The MFA Identity Trap: When Authentication Creates a False Sense of Security MFA protects 70% of enterprise users but do
Cybersecurity commentators are warning that multi-factor authentication, despite protecting roughly 70% of enterprise users, does not guarantee that a user's identity is genuinely legitimate. Attackers can sidestep MFA through account recovery flows and session hijacking exploits, meaning it proves control of an authenticator rather than true identity. Security professionals are debating how organisations should treat MFA as one layer, not proof of trustworthiness.