#identity
5 articles

SPIFFE/SPIRE Identity Spoofing: Root on K8s Node Harvests SVIDs
Unit 42 shows root on a Kubernetes node lets attackers spoof cgroup metadata and harvest co-located SPIFFE/SPIRE workload SVIDs, with a new tool, Spooffe, to test exposure.
HIGHIdentity-Based Attacks Dominate Breaches as Attackers Bypass Exploits
The Hacker News reports identity-based attacks, using stolen credentials and MFA bypass, are the dominant initial access vector in modern breaches, rendering sophisticated exploits unnecessary for initial entry.
HIGHTycoon 2FA Phishing Group Shifts to Device Code Attacks
The Tycoon 2FA phishing group has abandoned its namesake toolkit, adopting device code phishing to bypass multi-factor authentication and compromise Microsoft 365 and Gmail accounts.
HIGHAttackers Shift from Phishing to Social Engineering for Okta Compromise
Threat actors are bypassing email security by using phone-based social engineering to target IT help desks and compromise Okta identity systems, enabling initial access to corporate networks.
HIGHCredential-Based Attacks Blur Line Between Breach and Normal Activity
Modern attackers are exploiting valid credentials and living-off-the-land techniques to make breaches indistinguishable from legitimate user activity, rendering traditional perimeter and anomaly detection ineffective.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.