Tag: identity security
Cybersecurity Threat Advisory: TrustSink attack targets Microsoft Entra ID
TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model. It uses a rogue MFA provider to intercept user credentials during legitimate login attempts. The attack captures plaintext passwords in real time without the user’s knowledge. Attackers...
Why MSPs need a unified IAM platform to scale securely
With identity becoming the new security perimeter, many MSPs are looking for ways to simplify identity and access management (IAM) while delivering stronger protection to their customers. Consolidating essential identity security capabilities into a single platform can help reduce operational...
How MSPs can reduce risk with Privileged Access Management (PAM)
Identity is the new attack surface. Microsoft’s Digital Defense Report found that identity-based attacks surged 32 percent in the first half of 2025, with more than 97 percent involving password attacks. Why PAM is a must-have For MSPs, the risk is amplified because technicians often have privileged...
Why MFA fatigue attacks keep working
MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...
When MFA isn’t enough: The session hijacking problem
Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...
