All CosmicBytez Labs articles tagged #MFA Bypass, across news, security advisories, how-to guides, and projects.
New research from CTM360 shows that phishing campaigns targeting insurance and financial portals have moved beyond simple credential harvesting. Attackers...
Cisco Talos has uncovered ARToken, a Phishing-as-a-Service platform affiliated with EvilTokens that weaponizes Microsoft's OAuth device code flow to...
A two-week password-spray campaign generated over 81 million Microsoft 365 login attempts against 64 organizations, exploiting misconfigured MFA policies...
Threat actors brute-forced credentials and bypassed multi-factor authentication on SonicWall Gen6 SSL-VPN appliances to deploy ransomware tools,...
The Tycoon2FA phishing-as-a-service platform has added device-code phishing to its arsenal and abuses Trustifi click-tracking URLs to bypass Microsoft 365...
Infostealers are harvesting credentials and session cookies at scale, quietly bypassing MFA and traditional defenses. Here's why organizations need...
An international coalition led by Europol and Microsoft has taken down Tycoon2FA, a phishing-as-a-service platform responsible for 87.5 million phishing...