The future of MFA is clear – but is it here yet?
Not all authentication is equal to the task in 2025, but there is a best choice within reach
Not all authentication is equal to the task in 2025, but there is a best choice within reach
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three security flaws, each impacting AMI MegaRAC, D-Link DIR-859 router, and Fortinet FortiOS, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The list of vulnerabilities is as follows – CVE-2024-54085 (CVSS score: 10.0) – An authentication bypass by spoofing
The financially motivated threat group used cloud resources to conduct a complex, ransomware-style attack against an enterprise victim.
Researchers characterize the company’s artificial intelligence chatbot as less secure than ChatGPT and even DeepSeek.
Mass scanning is underway for CVE-2026-20045, which Cisco tagged as critical because successful exploitation could lead to a complete system takeover.
The phishing campaign shows how attackers continue to weaponize legitimate cloud services and open source tools to evade detection and gain trust.
The company expects it will continue to struggle with online disruptions until at least July, due to the attack.