MSMd Shakawat Hossaininthinking-journal.hashnode.dev·Jul 26 · 6 min readMulti-Factor Authentication (MFA): Why Everyone Needs ItToday, our digital identity is more valuable than ever. Emails, social media accounts, banking apps, cloud storage, developer platforms and business systems all depend on one important thing: authenti00
VNVũ Nhật Lâminblog.fiscybersec.com·Jul 19 · 10 min readARToken & EvilTokens: The AI-Augmented Device Code Phishing PhaaS Hijacking Microsoft 365 and Automating BEC FraudExecutive Summary ARToken is a Phishing-as-a-Service (PhaaS) operator panel published by Cisco Talos on July 1, 2026, which Talos assesses to be an affiliate panel of the EvilTokens platform — the Pha00
LTLưu Tuấn Anhinblog.fiscybersec.com·Jul 14 · 15 min readToddyCat and Umbrij: When OAuth Becomes the New Target of APT CampaignsOverview The recent campaign recorded by the APT ToddyCat group targets businesses using the Google Workspace (Gmail) email service. By using a specialized tool called Umbrij, attackers do not try to 00
EJEric James BAYSSETTEinejbye7.hashnode.dev·Jun 16 · 2 min readSecurity controls matter. Evidence makes them defensibleThis is becoming a practical rule in cybersecurity. It is no longer enough to say that MFA is deployed. It is no longer enough to say that privileged access is controlled. It is not enough to say that00
SKSahil Khuranaininnostaxengineering.hashnode.dev·Jun 8 · 7 min readGoogle Authenticator integration with Spring BootPasswords alone just don't cut it anymore. We've all seen the headlines — data breaches, credential stuffing, account takeovers. And yet, a shocking number of applications still rely on a single passw00
LTLưu Tuấn Anhinblog.fiscybersec.com·May 30 · 15 min readStorm-2949: Hacker Group Turns MFA Into a "Golden Key" to Steal Azure DataSummary of the campaign The new attack campaign by threat actor group Storm-2949 has raised alarms about the risks of identity self-service features in cloud computing environments. By exploiting the 20
NGNiranjan Ginblog.securityinsights.io·May 25 · 6 min readThe Hidden Threat After Login: Understanding Session HijackingYou did everything right. You turned on multi-factor authentication (MFA). You use strong passwords. Maybe you even switched to passkeys. So how did an attacker still get into your email? The answer i00
KKKabya Khanalinignitesecurity.hashnode.dev·May 18 · 3 min readHow Everyday Habits Stop Cyber ThreatsMost cyber breaches begin not with a crazy exploit, but with a preventable human action many people use a reused password, have a delayed update, or a single rushed click. The simplest defenses are di10
HHugoinhugovalters.hashnode.dev·Apr 17 · 3 min readMFA Fatigue: Why Your 'Secure' Push Notifications Are Getting You HackedCompanies will spend $50,000 a year on a premium Identity Provider (IdP) tier, roll out an authenticator app to the entire org, and proudly declare themselves "unhackable" at the next board meeting. Then Kevin in Sales gets his password scraped by a...00
HCHazel Chirindainhazelchirinda.hashnode.dev·Apr 13 · 3 min readNavigating Security Challenges When Clients Don’t Have IT TeamsWorking with clients who don’t have dedicated IT teams is one of the most challenging yet rewarding experiences in cybersecurity consulting. Without internal experts, every problem — from configuratio00