The Fake Passkey Call That Beat Their Cybersecurity Team
A fake IT call and a bogus passkey setup page are enough to take over Microsoft 365 accounts. Here's how cybersecurity teams close that gap.
A fake IT call and a bogus passkey setup page are enough to take over Microsoft 365 accounts. Here's how cybersecurity teams close that gap.
Fake "you've been reported" DMs are the newest cybersecurity blind spot, phishing MFA codes in real time. Here's how to actually stop it.
Callback phishing now hides inside trusted apps with no link to block. See why your firewall misses it and what stops it. Start here.
The FBI nuked a million phishing URLs this week. The credentials already moved. Here's where cybersecurity defenders should actually invest next.
Phishing volume fell 20 percent while breach risk climbed. Here's why your cybersecurity dashboards lie, and what to harden first this month.
Teams federation defaults turned "Hi, this is IT" into a cybersecurity disaster. Here's the configuration and detection work that actually shuts it down.
SVG phishing attachments are slipping past mail filters that trust the image extension. Here's the gap and how to close it before users click.
A Signal phishing wave skips the encryption and goes straight for backup recovery keys. Here's the cybersecurity gap to close this week.
ChatGPT share links and Markdown rendering are now phishing infrastructure. Here's why domain trust is failing and what to check first.
Tycoon2FA's new device-code phishing flow hijacks Microsoft 365 sessions without stealing a password. Here's what actually stops it.