MikeTrendsTrends right now

search

multi-factor authentication

Trends

  1. 1
    ASOS hit by extortion attack linked to Snowflake cloud breach▼ASOS Snowflake Cloud Breach: Cybersecurity Incident Analysis of Push Notification Extortion Attack✉newsTechnologyCybersecurity1 d ago

    Online fashion retailer ASOS is reported to have been caught up in the wave of Snowflake cloud data breaches, with attackers allegedly using push notification-based extortion to demand payment. Security analysts are examining the incident as part of the broader campaign targeting companies that stored customer data on Snowflake without multi-factor authentication.

  2. 2
    The synthetic voice trap in financial operations▼The synthetic voice trap: Moving beyond acoustic trust in financial operations✉newsTechnology1 d ago

    Credit unions are being warned that voice alone can no longer be trusted to verify callers in financial operations. As synthetic voice technology grows more convincing, fraudsters can imitate customers and staff, and institutions that rely on acoustic cues for authentication face real risk. The argument is that financial firms should move toward stronger, multi-factor verification rather than trusting how a voice sounds.

  3. 3
    Trump Mobile data breach exposes 3,615 customers●Trump Mobile data breach: BYOD leaks Trump Mobile customer data for 3,615 people, including Trump allies, via an infosteMmastodonTechnologyCybersecurity22 d ago

    A data breach at Trump Mobile has exposed personal information for 3,615 customers, reportedly including allies of Donald Trump. The leak stems from a bring-your-own-device setup compromised by an infostealer, with the account lacking multi-factor authentication. Security outlets are highlighting the incident as an example of how BYOD policies and missing MFA leave sensitive customer data open to theft.

  4. 4
    Fake ChatGPT and Gemini sites phish ad accounts●Fake ChatGPT, Gemini sites phish ad accounts and MFA codes https:// fawkes.rocks/2026/10/06/fake-c hatgpt-gemini-sites-pMmastodonTechnologyAI21 d ago

    Security researchers are warning about fraudulent websites imitating ChatGPT and Gemini that trick users into handing over advertising account credentials and multi-factor authentication codes. The fake AI tool pages are used to harvest logins, potentially giving attackers control of victims' ad accounts and bypassing two-factor security. Users are being urged to verify URLs and treat unsolicited AI tool links with caution.

  5. 5
    Fake ChatGPT and Gemini sites steal ad accounts and MFA codes●Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes https://www. bleepingcomputer.com/news/secu rity/fake-cMmastodonTechnologyAI01 d ago

    Fraudulent websites impersonating ChatGPT and Gemini are tricking users into handing over advertising account credentials and multi-factor authentication codes, according to a report by BleepingComputer. The fake AI sites harvest logins used for Google and Microsoft advertising platforms, potentially letting attackers hijack ad accounts and run costly fraudulent campaigns. Security researchers are warning businesses to verify URLs before signing in.

  6. 6
    Small business cybersecurity: low-cost basics that stop most attacks●Small business cybersecurity: The low-cost basics that stop most attacks✉newsBusiness1 d ago

    Guidance is circulating on affordable cybersecurity fundamentals for small businesses, arguing that basic low-cost measures — such as strong passwords, multi-factor authentication, software updates and staff awareness — can prevent the majority of common attacks. Small firms are often targeted because they lack dedicated security teams, and owners are being encouraged to prioritise these simple defenses over expensive solutions.

  7. 7
    Keycloak flaw lets stolen passwords bypass mandatory MFA●CVE-2026-105305 affects Red Hat build of Keycloak. The OIDC Device Authorization Grant flow does not enforce a client'sMmastodonTechnologyCybersecurity12 d ago

    A vulnerability tracked as CVE-2026-105305 affects the Red Hat build of Keycloak. The OIDC Device Authorization Grant flow fails to enforce a client's minimum authentication level, meaning a stolen password could bypass mandatory multi-factor authentication and gain access to the Admin REST API. No exploitation has been confirmed, and Red Hat has a fix available. Security practitioners are sharing the advisory and urging admins to patch promptly.

  8. 8
    Workers increasingly forced to use personal phones for work MFA●I don’t know when we crossed into this weird world of “you WILL use your personal mobile device to do MFA and we will NOMmastodonTechnologyCybersecurity32 d ago

    A cybersecurity worker is voicing frustration that many employers now require staff to install multi-factor authentication apps on their personal mobile phones without reimbursing the cost, with the complaint striking a chord among people in tech and security circles. The broader debate centres on whether companies should provide dedicated devices or compensate employees when personal hardware is effectively commandeered for workplace security.

  9. 9
    Swiss government login AGOV allows multi-factor account sharing●MFA und Account Sharing schlossen sich bis jetzt aus, das Schweizer Behörden Login # AGOV ermöglicht nun genau das 😱 httMmastodonTechnologyCybersecurity12 d ago

    The Swiss authorities' login system AGOV now offers a shared-use feature, allowing several people to use the same account even when multi-factor authentication is enabled. Commenters in the cybersecurity community have reacted with alarm, pointing out that MFA and account sharing have traditionally been considered mutually exclusive, and questioning how the feature affects accountability and security for government services.

  10. 10
    Simple settings changes could protect you from AI hackers●Simple settings changes that could protect you from AI hackers✉newsTechnologyAI2 d ago

    Scammers are increasingly using artificial intelligence to craft convincing phishing messages, voice clones and fake identities, and security reporters are urging people to act. Practical steps being highlighted include turning on multi-factor authentication, tightening privacy settings, limiting what personal information is publicly visible, and being skeptical of urgent requests, even when they appear to come from someone you know.