Pushing Your Way In
ID: 9ed3de4f-f641-5711-a316-efd81a3025cb
STIX ID: report--9ed3de4f-f641-5711-a316-efd81a3025cb
Feed Name: Black Hills Infosec Blog
The report outlines how attackers increasingly exploit stolen credentials through password spraying and bypass multi-factor authentication using reverse-proxy toolkits (CredSniper, Modlishka, Evilginx2) and push-notification fatigue. It highlights that some services validate credentials before enforcing the second factor, enabling credential verification and identification of accounts lacking MFA, and recommends user training to recognize indicators such as unsolicited phone verifications, unexpected push prompts, and new device/location sign-ins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
