Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish attack
ID: 927f0463-ae18-5a9b-ba1a-0c1feac499e0
STIX ID: report--927f0463-ae18-5a9b-ba1a-0c1feac499e0
Feed Name: The Register (Security)
Cisco warned that a Duo telephony subcontractor suffered a phishing-driven credential compromise on April 1 that allowed attackers to download SMS message logs (phone numbers, countries/states, timestamps, carriers) for messages sent in March 2024, though message content was not accessed. Separately, Cisco Talos is tracking a global, TOR-sourced increase in brute-force/password-spray activity since mid-March targeting VPNs, web authentication interfaces, and SSH across multiple vendors; Cisco advises logging, hardening default VPN profiles, and blocking malicious sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
