Device code phishing enabled hackers to bypass multifactor authentication without credentials.
Related Articles
All CyberSecurityDive →Voice channels are the next major attack vector that security teams can’t monitor
For years, cybersecurity teams have worked to close gaps across email, endpoints, cloud infrastructure, and application layers. But as new threats like deepfake voices infiltrate…
Corporate executives face mounting digital threats as AI drives impersonation
Corporate executives are facing a rise in impersonation-based cyberattacks aimed at gaining access to their home networks and putting them and their families at risk…
DHS warns of heightened cyber threat as US enters Iran conflict
The Department of Homeland Security warned Sunday of a higher risk of malicious cyber activity from Iran following the direct U.S. military intervention in Israel’s…
Bridgestone Americas continues probe as it looks to restore operations
Bridgestone Americas is continuing to investigate a cyberattack that disrupted operations at certain facilities and said it expects to return to normal operations within days. …
Landmark US cyber information-sharing program expires, bringing uncertainty
Listen to the article 5 min This audio is auto-generated. Please let us know if you have feedback. A federal program that encourages companies to…
CISA details security lapses that led to GitHub leak of passwords, cloud access keys
Weak security controls around the use of public GitHub code repositories allowed a contractor for the Cybersecurity and Infrastructure Security Agency (CISA) to accidentally leak…

