Tag: MFA

Why MFA fatigue attacks keep working

Why MFA fatigue attacks keep working

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...

/ July 21, 2026
When MFA isn’t enough: The session hijacking problem

When MFA isn’t enough: The session hijacking problem

Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...

/ July 14, 2026
How MSPs close the cloud migration security gap

How MSPs close the cloud migration security gap

When a client migrates to Microsoft 365 or Google Workspace, the instinct is to declare victory once emails are flowing, files are accessible, and users are productive again. The project feels complete. Except it isn’t, because security didn’t make the...

/ May 5, 2026
MFA fatigue continues to be a threat in 2026

MFA fatigue continues to be a threat in 2026

MFA fatigue attacks are rising—and succeeding—because users are overwhelmed. Logging in no longer means simply entering a password. It often requires a code sent to a device, scanning a prompt, or approving an authentication request. According to recent Microsoft data,...

/ January 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FortiOS CLI command bypass vulnerability

Cybersecurity Threat Advisory: FortiOS CLI command bypass vulnerability

Fortinet has disclosed a high-severity vulnerability in FortiOS, identified as CVE-2025-58325, which has a CVSS score of 7.8. This flaw could allow local authenticated attackers to execute arbitrary system commands. The vulnerability stems from improper input validation in the FortiOS...

/ October 20, 2025
Tech Time Warp
Tech Time Warp: The multifaceted road to multifactor authentication

Tech Time Warp: The multifaceted road to multifactor authentication

In the recent edition of “Oh Behave!,” the annual cybersecurity survey conducted by the National Cybersecurity Alliance, an alarming 44 percent of respondents said they had experienced cybercrime leading to the loss of data or money. This next statistic may...

/ October 17, 2025
MSPs: Stop account takeovers (ATO) cold

MSPs: Stop account takeovers (ATO) cold

Account takeover (ATO) cyberattacks are a particularly pernicious and challenging threat to combat. They have only grown more complex as credential management becomes increasingly intricate across organizations. According to a recent Barracuda 2025 Email Threats Report, 20% of companies experience...

/ August 6, 2025
phishing
An MSP’s guide to keeping up with phishing

An MSP’s guide to keeping up with phishing

Phishing has long been a primary tool in the hacker’s arsenal, but like military weapons, their tactics evolve. A phishing attempt in 2025 looks different from those in 2015, 2020, or even last year. Therefore, managed service providers (MSPs) must...

/ June 10, 2025
The MSP’s guide to creating a zero trust atmosphere

The MSP’s guide to creating a zero trust atmosphere

Zero trust in the workplace is typically a bad thing, fostering a culture of distrust and snitching. However, for managed service providers (MSPs), it is a good thing, at least when it comes to cybersecurity. Experts in the field say...

/ May 27, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical RCE flaw in Apache Roller blog server

Cybersecurity Threat Advisory: Critical RCE flaw in Apache Roller blog server

Researchers have discovered a critical session management vulnerability within Apache Roller. It is being tracked as CVE-2025-24859 and has been assigned the maximum CVSS score of 10.0. Review the details in this Cybersecurity Threat Advisory to mitigate your risks. What...

/ April 17, 2025