l+f: Nie mehr arbeiten dank Cybercrime

Ein BBC-Reporter erhält ein unmoralisches Angebot. Nimmt er es an?

heise online

Yubico Keys: A robust, user-friendly, phishing-resistant solution to MFA. Protects against cyber threats, drives productivity, and minimizes costs.

I believe that it’s imperative that we promote positive digital identity controls especially with generative AI ability to muck it up as a result of being used with malicious intent. #cybersecurity #mfabombing

MFA Bombing-Welle trifft Apple-Nutzer: Angreifer wollen Accounts übernehmen

MFA-Bombing-Attacken: Eine neue Phishing-Bedrohung für Apple-Nutzer. Was steckt dahinter und wie kann man sich schützen?

Tarnkappe.info
"Several #Apple customers recently reported being targeted in elaborate #phishing attacks that involve what appears to be a bug in Apple’s password reset feature. In this scenario, a target’s Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds 'Allow' or 'Don’t Allow' to each prompt."
#MFABombing #PeopleDataLabs #MFAFatigue #CyberAttack #CyberCrime #SpearPhishing
https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/
Recent ‘MFA Bombing’ Attacks Targeting Apple Users – Krebs on Security

Recent ‘MFA Bombing’ Attacks Targeting Apple Users – Krebs on Security

Recent ‘MFA Bombing’ Attacks Targeting Apple Users – Krebs on Security

Recent ‘MFA Bombing’ Attacks Targeting Apple Users - Several Apple customers recently reported being targeted in elaborate phishing att... https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/ #applerecoverykey #alittlesunshine #latestwarnings #thecomingstorm #peopledatalabs #kishanbagaria #mfabombing #mfafatigue #parthpatel #apple
Recent ‘MFA Bombing’ Attacks Targeting Apple Users – Krebs on Security

My team just released a new MFA bombing testing tool. It can be used in purple & red team modes to execute MFA fatigue/spamming/bombing on #Okta users. After we'll add more IdPs
AFAIK it is the first MFA bombing tool for Okta.

Https://github.com/authomize/mfa-bombing

#mfa #mfabombing #purpleteam #blueteam #redteam #RedTeamBlues #toolbox #mfafatigue #purplet

GitHub - authomize/mfa-bombing

Contribute to authomize/mfa-bombing development by creating an account on GitHub.

GitHub

With the ever increasing attacks on users, moving to #multifactorauthentication is a must in order to reduce the attack surface of just relying on a password to secure access to resources. Implementing #MFA that is enforced all the time relies on also having a good user experience, which gave rise to mobile authenticator apps since many users always have their phones with them. However it also gave rise to #mfabombing and griefing to get those users to approve. With the recent GA of #microsoftauthenticator #azuread orgs can enable number match and context for the push notification to further improve the #security of the users by avoiding the blind approval of a push notification.

🔥 See the post on the AzureAD blog here and go enable these settings for your organization https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/advanced-microsoft-authenticator-security-features-are-now/ba-p/2365673 #microsoft #office365 #o365 #cloudsecurity

Advanced Microsoft Authenticator security features are now generally available!

After announcing the public preview of critical Microsoft Authenticator security features, we’re thrilled today to share that these features are now Generally Available for you to further secure your organization:    Admins can now prevent accidental approvals in Microsoft Authenticator with number...

TECHCOMMUNITY.MICROSOFT.COM