search
multi-factor authentication
Trends
- 1Fake ChatGPT and Gemini sites phish ad accountsโFake ChatGPT, Gemini sites phish ad accounts and MFA codes https:// fawkes.rocks/2026/10/06/fake-c hatgpt-gemini-sites-p
Security researchers are warning about fraudulent websites imitating ChatGPT and Gemini that trick users into handing over advertising account credentials and multi-factor authentication codes. The fake AI tool pages are used to harvest logins, potentially giving attackers control of victims' ad accounts and bypassing two-factor security. Users are being urged to verify URLs and treat unsolicited AI tool links with caution.
- 2Small business cybersecurity: low-cost basics that stop most attacksโSmall business cybersecurity: The low-cost basics that stop most attacks
Guidance is circulating on affordable cybersecurity fundamentals for small businesses, arguing that basic low-cost measures โ such as strong passwords, multi-factor authentication, software updates and staff awareness โ can prevent the majority of common attacks. Small firms are often targeted because they lack dedicated security teams, and owners are being encouraged to prioritise these simple defenses over expensive solutions.
- 3Fake ChatGPT and Gemini sites steal ad accounts and MFA codesโFake ChatGPT, Gemini Sites steal advertising accounts, MFA codes https://www. bleepingcomputer.com/news/secu rity/fake-c
Fraudulent websites impersonating ChatGPT and Gemini are tricking users into handing over advertising account credentials and multi-factor authentication codes, according to a report by BleepingComputer. The fake AI sites harvest logins used for Google and Microsoft advertising platforms, potentially letting attackers hijack ad accounts and run costly fraudulent campaigns. Security researchers are warning businesses to verify URLs before signing in.
- 4Trump Mobile data breach exposes 3,615 customersโTrump Mobile data breach: BYOD leaks Trump Mobile customer data for 3,615 people, including Trump allies, via an infoste
A data breach at Trump Mobile has exposed personal information for 3,615 customers, reportedly including allies of Donald Trump. The leak stems from a bring-your-own-device setup compromised by an infostealer, with the account lacking multi-factor authentication. Security outlets are highlighting the incident as an example of how BYOD policies and missing MFA leave sensitive customer data open to theft.
- 5Keycloak flaw lets stolen passwords bypass mandatory MFAโCVE-2026-105305 affects Red Hat build of Keycloak. The OIDC Device Authorization Grant flow does not enforce a client's
A vulnerability tracked as CVE-2026-105305 affects the Red Hat build of Keycloak. The OIDC Device Authorization Grant flow fails to enforce a client's minimum authentication level, meaning a stolen password could bypass mandatory multi-factor authentication and gain access to the Admin REST API. No exploitation has been confirmed, and Red Hat has a fix available. Security practitioners are sharing the advisory and urging admins to patch promptly.