ZCyberNews
中文

#mfa-bypass

6 articles

Business services and enterprise organizations were the primary targets in the nine high-severity incidents tracked under the mfa-bypass tag between April and August 2026. Global operations, particularly those in Canada and North America, faced the most significant impact. Storm-2755 and Tycoon 2FA were observed as separate threat actors in these campaigns. The affected sectors included finance and financial services, alongside the broader business services and enterprise categories. All reported cases were rated high severity, underscoring the consistent risk posed to authentication systems across these regions and industries.

Diagram of a multi-stage adversary-in-the-middle phishing attack using cloud servicesHIGH
Malware

GitHub Pages, Cloudflare Workers Fuel MFA-Bypass Phishing

Kaspersky details a cloud-based AitM phishing campaign abusing GitHub Pages and Cloudflare Workers to bypass MFA via service workers and Ultraviolet proxy.

4 min read
Deepfake Voice Attacks Outpace Defenses, Bypass MFAHIGH
Industry News

Deepfake Voice Attacks Outpace Defenses, Bypass MFA

Adaptive Security finds 3 seconds of audio enough to clone a voice for fraud; deepfake calls tricked employees into wiring $243K in one case. No detection tool caught the attack.

2 min read
Tycoon 2FA Phishing Kit Disruption Fuels Surge in Copycat AttacksHIGH
Threat Intel

Tycoon 2FA Phishing Kit Disruption Fuels Surge in Copycat Attacks

The disruption of the Tycoon 2FA phishing-as-a-service platform has led to a surge in copycat attacks, as threat actors reuse its tools and techniques in other kits, increasing the overall volume of multi-factor authentication bypass attempts.

4 min read
Tycoon 2FA Phishing Group Shifts to Device Code AttacksHIGH
Threat Intel

Tycoon 2FA Phishing Group Shifts to Device Code Attacks

The Tycoon 2FA phishing group has abandoned its namesake toolkit, adopting device code phishing to bypass multi-factor authentication and compromise Microsoft 365 and Gmail accounts.

4 min readTycoon 2FA
Attackers Shift from Phishing to Social Engineering for Okta CompromiseHIGH
Threat Intel

Attackers Shift from Phishing to Social Engineering for Okta Compromise

Threat actors are bypassing email security by using phone-based social engineering to target IT help desks and compromise Okta identity systems, enabling initial access to corporate networks.

4 min read
Storm-2755 Hijacks Payroll via AiTM AttacksHIGH
Threat Intel

Storm-2755 Hijacks Payroll via AiTM Attacks

Financially motivated group Storm-2755 targets Canadian employees using AiTM session hijacking to redirect salary payments.

2 min readStorm-2755

Stay Updated

Get the latest cybersecurity news delivered to your inbox.