CISA Warns of Widespread FortiBleed Attacks on 86,644 Devices

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning after a massive cyberattack, dubbed FortiBleed, compromised a staggering 86,644 FortiGate devices, putting countless networks at risk. Take immediate action to protect yourself: shut down active SSL VPN and admin sessions, reset passwords, and enforce strong password policies.

https://osintsights.com/cisa-warns-of-widespread-fortibleed-attacks-on-86644-devices?utm_source=mastodon&utm_medium=social

#Fortibleed #Cisa #Fortinet #SslVpn #MfaBypass

CISA Warns of Widespread FortiBleed Attacks on 86,644 Devices

Protect your FortiGate devices from widespread FortiBleed attacks. Learn immediate steps to secure your system and prevent further breaches now with expert guidance.

OSINTSights

SimpleHelp vulnerability exposes servers to rogue remote support accounts

A critical vulnerability in SimpleHelp, known as CVE-2026-48558, lets hackers create rogue remote support accounts and gain privileged access to servers, allowing them to execute scripts and wreak havoc on your system. This gaping security hole enables unauthenticated attackers to bypass multi-factor authentication and log in as a…

https://osintsights.com/simplehelp-vulnerability-exposes-servers-to-rogue-remote-support-accounts?utm_source=mastodon&utm_medium=social

#Cve202648558 #OpenidConnect #Oidc #MfaBypass #Vulnerability

SimpleHelp vulnerability exposes servers to rogue remote support accounts

Learn how CVE-2026-48558 exposes SimpleHelp servers to rogue remote support accounts and take immediate action to secure your servers now with expert guidance.

OSINTSights

The Silent Breach and the Persistence of Unauthorized Access

938 words, 5 minutes read time.

Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

Challenging the Failure of Traditional Defensive Postures

When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

Implementing Rigorous Verification Protocols in a High-Stakes Environment

The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

Call to Action

The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

SUPPORTSUBSCRIBECONTACT ME

D. Bryan King

Sources

Disclaimer:

The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

#accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust

Threat Actors Exploit Microsoft Teams for Phishing Attacks

Phishing attacks are getting smarter, with threat actors now using trusted platforms like Microsoft Teams to target unsuspecting employees, accounting for 42% of all phishing alerts in just the first four months of 2026. These sneaky messages can land directly in your feed, masquerade as internal IT support, and trick you into taking…

https://osintsights.com/threat-actors-exploit-microsoft-teams-for-phishing-attacks?utm_source=mastodon&utm_medium=social

#Phishing #MicrosoftTeams #SocialEngineering #MfaBypass #CollaborationTools

Threat Actors Exploit Microsoft Teams for Phishing Attacks

Learn how threat actors exploit Microsoft Teams for phishing attacks and protect your organization from these targeted threats today with expert security tips.

OSINTSights

Meta AI Flaw Compromises 20,000 Instagram Accounts

A bug in Meta's AI-powered support feature, High Touch Support, allowed outsiders to access nearly 20,000 Instagram accounts by exploiting a flaw that failed to verify email addresses for password reset requests. This oversight enabled hackers to bypass security checks and gain unauthorized account access.

https://osintsights.com/meta-ai-flaw-compromises-20000-instagram-accounts?utm_source=mastodon&utm_medium=social

#Instagram #MetaAi #HighTouchSupport #Hts #MfaBypass

Meta AI Flaw Compromises 20,000 Instagram Accounts

Discover how Meta's High Touch Support flaw compromised 20,000 Instagram accounts. Learn more about the AI-powered tool vulnerability and take steps to secure your account now.

OSINTSights

Ransomware Gang Pink Exploits Helpdesk Calls to Steal Credentials

Meet Pink, a notorious ransomware gang that's exploiting helpdesk calls to steal sensitive credentials using clever tactics like vishing and IT impersonation. They're using these stolen secrets to exfiltrate valuable data from enterprise cloud storage and productivity systems, leaving victims with a tough choice: pay up or face the consequences.

https://osintsights.com/ransomware-gang-pink-exploits-helpdesk-calls-to-steal-credentials?utm_source=mastodon&utm_medium=social

#Ransomware #Pink #MfaBypass #Vishing #ItImpersonation

Ransomware Gang Pink Exploits Helpdesk Calls to Steal Credentials

Learn how Pink ransomware gang exploits helpdesk calls to steal credentials and extort victims, and take action to protect your enterprise from this threat now.

OSINTSights

Microsoft 365 Android Apps Expose Account Tokens Due to Debug Flag Oversight

A single line of code, "setIsDebugMode(true)," inadvertently left in multiple Microsoft 365 Android apps, created a gaping security hole that allowed other apps on the same phone to access sensitive account tokens without user permission. This tiny oversight, discovered by Enclave's Yanir Tsarimi and Ofek Levin, exposed users…

https://osintsights.com/microsoft-365-android-apps-expose-account-tokens-due-to-debug-flag-oversight?utm_source=mastodon&utm_medium=social

#Microsoft365 #Android #DebugFlag #AccountTokenExposure #MfaBypass

Microsoft 365 Android Apps Expose Account Tokens Due to Debug Flag Oversight

Learn how a debug flag oversight in Microsoft 365 Android apps exposed account tokens and how to protect yourself from similar security risks now.

OSINTSights

Browser Becomes Front Line in AI Security Battle

The battle for AI security is heating up, and the browser has become the front line - with security teams facing a double threat of AI-powered attacks converging in this critical space. Attackers are leveraging AI to supercharge phishing techniques, including device code phishing kits that have surged 18x in just one year.

https://osintsights.com/browser-becomes-front-line-in-ai-security-battle?utm_source=mastodon&utm_medium=social

#AiSecurity #DeviceCodePhishing #OauthAbuse #MfaBypass #EmergingThreats

Browser Becomes Front Line in AI Security Battle

Learn how AI security threats in browsers are evolving and take action to protect against device code phishing and emerging threats now.

OSINTSights
FIDO vs FIDO2: Understanding the Evolution of Passwordless Authentication

Explore the evolution from FIDO to FIDO2 and learn how modern passwordless authentication enhances security and user experience in DevOps environments.

IAMDevBox
MFA Bypass Attacks: Understanding Threats and Implementing Phishing-Resistant Authentication

MFA bypass attacks explained — malware-based OTP interception, adversary-in-the-middle (AiTM) phishing, SIM swapping, and MFA fatigue. Learn to implement phishing-resistant FIDO2/WebAuthn passkeys and Conditional Access to block all bypass methods.

IAMDevBox