Tag

Two Factor Authentication

All articles tagged with #two factor authentication

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11
technology9 days ago

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11

Microsoft will stop using SMS verification for personal Microsoft accounts, phasing out SMS as a method for two-factor authentication and account recovery in favor of passwordless options like passkeys, authenticator apps, and verified backup emails. Microsoft argues SMS is insecure and a frequent fraud vector (including SIM-swaps), and promotes passkeys that rely on device biometrics and hardware-backed keys. The transition is cross-device compatible but may cause friction for power users and scenarios like virtual machines where a hardware-based sign-in isn’t available.

technology9 days ago

Hackers Exploit Minimal Data to Hijack PSN Accounts

Insider Gaming reports a security flaw in PlayStation Network where attackers can hijack PSN accounts using only a public PSN ID and a piece of old transaction data, with Sony support potentially bypassing standard protocols to change the account email and disable 2FA; the revelation follows high-profile hacks like Colin Moriarty’s, underscoring rising risks and prompting calls for Sony to respond and for users to protect their PSN IDs.

AI-Driven Zero-Day Discovery Linked to 2FA Target, Google Says
cybersecurity16 days ago

AI-Driven Zero-Day Discovery Linked to 2FA Target, Google Says

Google’s Threat Intelligence Group says a prominent cybercrime group used an AI-assisted zero-day in a Python script to target a popular open-source web-based system administration tool, potentially bypassing two-factor authentication; Google and the vendor coordinated a disclosure and patch, noting Gemini was not involved and that the attackers likely leveraged AI to discover and weaponize the flaw, amid broader debates around Mythos hype.

AI-Designed Zero-Day Bypasses 2FA in Mass Exploitation Campaign
cybersecurity17 days ago

AI-Designed Zero-Day Bypasses 2FA in Mass Exploitation Campaign

Google Threat Intelligence Group revealed a zero-day exploit—likely AI-assisted—that enables bypassing 2FA on a popular open-source admin tool and was used in a mass exploitation campaign; the Python-based exploit shows patterns typical of LLM-generated code, and Google coordinated with the vendor to patch the flaw and disrupt the operation, while the report also highlights broader AI-enabled threats including autonomous malware and AI-assisted misuse of Gemini.

Urgent: Gmail Users Must Change Passwords After Massive Data Breach
technology9 months ago

Urgent: Gmail Users Must Change Passwords After Massive Data Breach

Google warns that Gmail accounts are under increasing attack, with scammers impersonating Google support to hijack accounts. Users are advised to verify account activity through official channels, strengthen security with strong passwords, and enable two-factor authentication. Despite clarifications that recent breaches did not affect data, the threat of account hijacking remains high, emphasizing layered security practices.

Steps to Take When Receiving Unsolicited Password Reset Emails
security11 months ago

Steps to Take When Receiving Unsolicited Password Reset Emails

Receiving an unexpected password reset email can indicate hacking attempts, phishing, or account compromise. It's crucial to avoid clicking links, check recent account activity, change passwords, scan devices for malware, and report suspicious activity to protect personal information. Regularly reviewing account settings and enabling two-factor authentication enhances security.