Tag

Two Factor Authentication

All articles tagged with #two factor authentication

technology24 days ago

AI-powered phishing scams: seven schemes you need to know

AI-generated phishing emails are becoming almost indistinguishable from legitimate messages, and attackers use new tricks like OAuth device code flows to bypass MFA and QR codes to hide links. The piece outlines seven current scams—Microsoft 365 login theft, support scams, fake Defender warnings, cloud/OneDrive phishing, parcel-delivery impersonations, online-banking fraud, and Postident fraud by post—and provides practical defenses: verify via official sites, enable MFA, use a password manager, avoid clicking links or scanning unknown QR codes, and resist unsolicited remote-support requests.

Hack Leads to Suspended Microsoft Account, Wiped OneDrive, and Lost Purchases
technology1 month ago

Hack Leads to Suspended Microsoft Account, Wiped OneDrive, and Lost Purchases

A compromised Microsoft account was permanently suspended and the user’s OneDrive data wiped, forcing the owner to reopen a new account and repurchase all games tied to the old account. Microsoft says the data can’t be recovered due to encryption and notes the user hadn’t enabled two-factor authentication, while recommending passkeys. The episode underscores the risks of digital ownership and cloud dependencies as tech giants move away from physical media and toward digital storefronts.

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11
technology3 months ago

Microsoft ends SMS sign-ins, doubles down on passwordless on Windows 11

Microsoft will stop using SMS verification for personal Microsoft accounts, phasing out SMS as a method for two-factor authentication and account recovery in favor of passwordless options like passkeys, authenticator apps, and verified backup emails. Microsoft argues SMS is insecure and a frequent fraud vector (including SIM-swaps), and promotes passkeys that rely on device biometrics and hardware-backed keys. The transition is cross-device compatible but may cause friction for power users and scenarios like virtual machines where a hardware-based sign-in isn’t available.

technology3 months ago

Hackers Exploit Minimal Data to Hijack PSN Accounts

Insider Gaming reports a security flaw in PlayStation Network where attackers can hijack PSN accounts using only a public PSN ID and a piece of old transaction data, with Sony support potentially bypassing standard protocols to change the account email and disable 2FA; the revelation follows high-profile hacks like Colin Moriarty’s, underscoring rising risks and prompting calls for Sony to respond and for users to protect their PSN IDs.

AI-Driven Zero-Day Discovery Linked to 2FA Target, Google Says
cybersecurity3 months ago

AI-Driven Zero-Day Discovery Linked to 2FA Target, Google Says

Google’s Threat Intelligence Group says a prominent cybercrime group used an AI-assisted zero-day in a Python script to target a popular open-source web-based system administration tool, potentially bypassing two-factor authentication; Google and the vendor coordinated a disclosure and patch, noting Gemini was not involved and that the attackers likely leveraged AI to discover and weaponize the flaw, amid broader debates around Mythos hype.

AI-Designed Zero-Day Bypasses 2FA in Mass Exploitation Campaign
cybersecurity3 months ago

AI-Designed Zero-Day Bypasses 2FA in Mass Exploitation Campaign

Google Threat Intelligence Group revealed a zero-day exploit—likely AI-assisted—that enables bypassing 2FA on a popular open-source admin tool and was used in a mass exploitation campaign; the Python-based exploit shows patterns typical of LLM-generated code, and Google coordinated with the vendor to patch the flaw and disrupt the operation, while the report also highlights broader AI-enabled threats including autonomous malware and AI-assisted misuse of Gemini.

Urgent: Gmail Users Must Change Passwords After Massive Data Breach
technology1 year ago

Urgent: Gmail Users Must Change Passwords After Massive Data Breach

Google warns that Gmail accounts are under increasing attack, with scammers impersonating Google support to hijack accounts. Users are advised to verify account activity through official channels, strengthen security with strong passwords, and enable two-factor authentication. Despite clarifications that recent breaches did not affect data, the threat of account hijacking remains high, emphasizing layered security practices.