#MFA

[ follow ]
Information security
fromArs Technica
1 week ago

"Payroll Pirate" phishing scam that takes over Workday accounts steals paychecks

Attackers use phishing and adversary-in-the-middle techniques to steal Workday credentials and MFA codes, then change payroll settings to divert direct-deposit payments to their accounts.
fromTheregister
1 week ago

Microsoft warns of 'payroll pirate' attacks against US unis

In a blog post, Redmond said a cybercrime crew it tracks as Storm-2657 has been targeting university employees since March 2025, hijacking salaries by breaking into HR software such as Workday. The attack is as audacious as it is simple: compromise HR and email accounts, quietly change payroll settings, and redirect pay packets into attacker-controlled bank accounts. Microsoft has dubbed the operation "payroll pirate," a nod to the way crooks plunder staff wages without touching the employer's systems directly.
Information security
Information security
fromTechzine Global
1 week ago

Microsoft 365 outage disrupts Teams and Exchange access globally

Microsoft 365 outage causes widespread authentication and access failures across Teams, Exchange Online, and Entra, with MFA messages failing globally.
fromSecurityWeek
3 weeks ago

PyPI Warns Users of Fresh Phishing Campaign

The attack, a continuation of a campaign conducted in July, involves fraudulent messages asking users to verify their email address for security purposes, and claiming that accounts may be suspended due to lack of action. "This email is fake, and the link goes to pypi-mirror.org which is a domain not owned by PyPI or the PSF [Python Software Foundation]," PSF security developer-in-residence Seth Larson warns. Setting up phishing-resistant multi-factor authentication (MFA), Larson explains, helps PyPI maintainers mitigate the risks associated with phishing attacks.
Information security
#identity-security
Privacy technologies
fromArs Technica
5 months ago

Phishing attacks that defeat MFA are easier than ever. So what are we to do?

WebAuthn authentication significantly enhances security against adversary-in-the-middle attacks by binding credentials to specific URLs and devices.
[ Load more ]