Tag

2fa Bypass

All articles tagged with #2fa bypass

Fortinet SSL VPN and FortiGate vulnerabilities under active attack

Originally Published 19 days ago — by The Hacker News

Featured image for Fortinet SSL VPN and FortiGate vulnerabilities under active attack
Source: The Hacker News

Fortinet has issued a warning about active exploitation of a five-year-old vulnerability in FortiOS SSL VPN (CVE-2020-12812) that allows attackers to bypass two-factor authentication under certain configurations, especially involving LDAP integration and case-sensitive username matching. Organizations are advised to update their systems or disable username sensitivity to mitigate the risk, and to contact support if they suspect exploitation.

Qantas Data Breach Exposes 6 Million Customers in Major Cyberattack

Originally Published 6 months ago — by Forbes

Featured image for Qantas Data Breach Exposes 6 Million Customers in Major Cyberattack
Source: Forbes

Following an FBI warning about 2FA bypass attacks, Qantas experienced a data breach affecting six million customers through a third-party platform, highlighting the increasing threat of targeted cyberattacks in the airline industry. Experts emphasize the importance of robust cybersecurity measures and cautious communication to mitigate risks and maintain trust.

FBI Warns of Rising 2FA Bypass Attacks and Aviation Cyber Threats

Originally Published 6 months ago — by Forbes

Featured image for FBI Warns of Rising 2FA Bypass Attacks and Aviation Cyber Threats
Source: Forbes

The FBI has issued a warning about the Scattered Spider threat group, which is expanding its attacks into the transportation and airline sectors by using social engineering to bypass multi-factor authentication, with a focus on impersonation and supply chain vulnerabilities. The group, linked to ransomware activities and collaborating with other threat actors, is also targeting the insurance industry, emphasizing the need for organizations to follow strict security protocols and remain vigilant against sophisticated social engineering tactics.