Tag

#MFA Bypass

5 articles covering MFA Bypass across campaign analysis, detection engineering, and defender tradecraft.

Coverage

5 entries

Field Analysis

Dual UseInfrastructure IntelligenceJun 7, 20269 min read

Kali365 Outgrows Microsoft 365: Operator Pivots to Okta, AWS, and a Russian-Language Cluster

Arctic Wolf's June 2 follow-up describes the Kali365 operator expanding well beyond Microsoft 365: Okta SSO, Xerox DocuShare, AWS-style endpoints, and a Russian-language cluster including MAX Messenger account takeover via real SMS OTPs. Proofpoint's research places the kit inside a broader cluster of AI-generated device-code lookalikes.

Field Analysis

Blue TeamDetection & ValidationMay 31, 20267 min read

Chrome Binds the Cookie: A Defender's Brief on Device Bound Session Credentials

Chrome's Device Bound Session Credentials, now generally available and on by default for Workspace, tie session cookies to a device's security chip so a stolen cookie is useless off the machine it came from. Here is what it stops and what it does not.

Browse Other Tags

#Detection Engineering#OAuth#Identity#Credential Theft#Supply Chain#AiTM#Campaign Analysis#Infrastructure Intelligence#SaaS Security#Tradecraft Labs#ClickFix#Initial Access