Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: mfa Clear Filter

Microsoft now enforces MFA on Azure Portal sign-ins for all tenants

Microsoft says it has been enforcing multifactor authentication (MFA) for Azure Portal sign-ins across all tenants since March 2025. The company's Azure MFA enforcement efforts were announced in May 2024 when Redmond began implementing mandatory MFA for all users signing into Azure to administer resources. One year ago, in August 2024, Microsoft also warned Entra global admins to enable MFA for their tenants by October 15, 2024, to ensure users don't lose access to admin portals. After comple

Microsoft to enforce MFA for Azure resource management in October

Starting in October, Microsoft will enforce multi-factor authentication (MFA) for all Azure resource management actions to protect Azure clients from unauthorized access attempts. This change is part of the company's Secure Future Initiative (SFI), will be applied gradually across tenants worldwide, and it requires users to enable MFA on Azure CLI, PowerShell, SDKs, and APIs to ensure that their accounts are protected against attacks. To avoid compatibility issues, users are also advised to up

Elon Musk’s “thermonuclear” Media Matters lawsuit may be fizzling out

Media Matters for America (MMFA)—a nonprofit that Elon Musk accused of sparking a supposedly illegal ad boycott on X—won its bid to block a sweeping Federal Trade Commission (FTC) probe that appeared to have rushed to silence Musk's foe without ever adequately explaining why the government needed to get involved. In her opinion granting MMFA's preliminary injunction, US District Judge Sparkle L. Sooknanan—a Joe Biden appointee—agreed that the FTC's probe was likely to be ruled as a retaliatory

Zero-day flaws in authentication, identity, authorization in HashiCorp Vault

Introduction: when the trust model can’t be trusted Secrets vaults are the backbone of digital infrastructure. They store the credentials, tokens, and certificates that govern access to systems, services, APIs, and data. They’re not just a part of the trust model, they are the trust model. In other words, if your vault is compromised, your infrastructure is already lost. Driven by the understanding that vaults are high-value targets for attackers, our research team at Cyata set out to conduct

Cracking the Vault: How we found zero-day flaws in HashiCorp Vault

Introduction: when the trust model can’t be trusted Secrets vaults are the backbone of digital infrastructure. They store the credentials, tokens, and certificates that govern access to systems, services, APIs, and data. They’re not just a part of the trust model, they are the trust model. In other words, if your vault is compromised, your infrastructure is already lost. Driven by the understanding that vaults are high-value targets for attackers, our research team at Cyata set out to conduct

MFA matters… But it isn’t enough on its own

Unprotected usernames and passwords offer little defense against account takeover attacks. Multi-factor authentication (MFA) has quite rightly become the de facto standard for strengthening access controls. There’s a reason almost all cybersecurity guidelines recommend it – Microsoft research suggests that enabling MFA can block over 99% of automated credential-stuffing and phishing attacks. Yet even the best MFA implementations leave a critical gap: weak, reused or compromised passwords. When

How attackers are still phishing "phishing-resistant" authentication

As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless, FIDO2-based authentication methods (aka. passkeys) like YubiKeys, Okta FastPass, and Windows Hello are being increasingly advocated. This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy “Attacker-in-the-Middle” phishing kits the most common method (and the standard choice for phishi

The MFA You Trust Is Lying to You – and Here's How Attackers Exploit It

Still getting login codes via text or authenticator apps? You’re not alone—and that’s a big problem. What used to feel like a smart security layer is now one of the easiest ways for attackers to gain access to your accounts. First we were told to use SMS for MFA. Then we were told: “Don’t use SMS for MFA, use an authenticator app instead.” And while that may seem like a step forward, it’s still fundamentally flawed. Authenticator apps do improve over SMS by avoiding message interception, but t

Nordic Semiconductor Acquires Memfault

Memfault has established itself as the leading platform provider for device observability and management, and secure over-the-air (OTA) software updates to ensure the highest device reliability without field returns. It is trusted by a growing developer community and customers to monitor, maintain, and scale connected products. Nordic will integrate Memfault’s capabilities across its complete product portfolio and into its existing nRF Cloud services platform, creating a significantly more power

Microsoft confirms auth issues affecting Microsoft 365 users

Microsoft is investigating an ongoing incident that is causing users to experience errors with some Microsoft 365 authentication features. As the company revealed earlier today in an incident alert published in the admin center, users may experience errors during self-service password resets, while admins may be unable to add multi-factor authentication (MFA) sign-in methods to some users. Redmond says this incident is caused by a recent change aiming to improve MFA sign-in functionality. Sinc