LTLưu Tuấn Anhinblog.fiscybersec.com·5d ago · 9 min readBypass MFA without unlocking: The stealth trick of malware targeting Google Password ManagerOverview Just by reading a local LevelDB file on the computer without requiring administrative rights (Admin/System), a common malware can now completely bypass Google's anti-phishing-resistant multi-00
FTFusionAuth teaminfusionauth.hashnode.dev·Aug 12 · 11 min readWhy Risk-Based MFA is a Game Changer for User ExperienceSecurity measures often feel like they’re just making life harder for customers. The problem is that too much friction can work against security. Frustrated users are more likely to reuse passwords, c00
MSMd Shakawat Hossaininthinking-journal.hashnode.dev·Jul 26 · 6 min readMulti-Factor Authentication (MFA): Why Everyone Needs ItToday, our digital identity is more valuable than ever. Emails, social media accounts, banking apps, cloud storage, developer platforms and business systems all depend on one important thing: authenti00
VNVũ Nhật Lâminblog.fiscybersec.com·Jul 19 · 10 min readARToken & EvilTokens: The AI-Augmented Device Code Phishing PhaaS Hijacking Microsoft 365 and Automating BEC FraudExecutive Summary ARToken is a Phishing-as-a-Service (PhaaS) operator panel published by Cisco Talos on July 1, 2026, which Talos assesses to be an affiliate panel of the EvilTokens platform — the Pha00
LTLưu Tuấn Anhinblog.fiscybersec.com·Jul 14 · 15 min readToddyCat and Umbrij: When OAuth Becomes the New Target of APT CampaignsOverview The recent campaign recorded by the APT ToddyCat group targets businesses using the Google Workspace (Gmail) email service. By using a specialized tool called Umbrij, attackers do not try to 00
EJEric James BAYSSETTEinejbye7.hashnode.dev·Jun 16 · 2 min readSecurity controls matter. Evidence makes them defensibleThis is becoming a practical rule in cybersecurity. It is no longer enough to say that MFA is deployed. It is no longer enough to say that privileged access is controlled. It is not enough to say that00
SKSahil Khuranaininnostaxengineering.hashnode.dev·Jun 8 · 7 min readGoogle Authenticator integration with Spring BootPasswords alone just don't cut it anymore. We've all seen the headlines — data breaches, credential stuffing, account takeovers. And yet, a shocking number of applications still rely on a single passw00
LTLưu Tuấn Anhinblog.fiscybersec.com·May 30 · 15 min readStorm-2949: Hacker Group Turns MFA Into a "Golden Key" to Steal Azure DataSummary of the campaign The new attack campaign by threat actor group Storm-2949 has raised alarms about the risks of identity self-service features in cloud computing environments. By exploiting the 20
NGNiranjan Ginblog.securityinsights.io·May 25 · 6 min readThe Hidden Threat After Login: Understanding Session HijackingYou did everything right. You turned on multi-factor authentication (MFA). You use strong passwords. Maybe you even switched to passkeys. So how did an attacker still get into your email? The answer i00
KKKabya Khanalinignitesecurity.hashnode.dev·May 18 · 3 min readHow Everyday Habits Stop Cyber ThreatsMost cyber breaches begin not with a crazy exploit, but with a preventable human action many people use a reused password, have a delayed update, or a single rushed click. The simplest defenses are di10