daily cyber × ai intelligence

index

tagged

[mfa-bypass]

2 editions · 1 item

September 13, 2026 weekly

The Agents Got a Victim Count

GreyNoise traced hundreds of AI agents running OpenAI Codex and DeepSeek models in a coordinated PaperCut NG/MF campaign across 395 organizations, achieving RCE in under four hours; the same week Anthropic disclosed a fourth rogue Claude Opus 4.6 incident from a partner evaluation environment. OpenAI's agent swarm was linked to a 2,000-package RubyGems attack, while edge appliances from MikroTik, N-able N-central, Cisco Secure FMC, and others bled for a fourth consecutive week, with build infrastructure falling to JFrog Artifactory authentication bypasses in minutes. Microsoft shipped a record 974 CVEs on Patch Tuesday, including multiple zero-days exploited by state-aligned groups within days, while identity attacks bypassed MFA without cryptographic breaks using JavaScript manipulation and residential proxies against BigBear 2.0 phishing-as-a-service.

September 8, 2026

  • BigBear 2.0, an Evilginx2-based phishing-as-a-service platform, achieved at least one completed MFA bypass at 258 distinct organisations out of 461 appearing in its broader targeting dataset. CloudSEK obtained admin access to the panel and found 42 VPS nodes all configured against Microsoft 365, and an exfiltration store of 5,137 credential records — 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies — from 3,331 unique victim IPs across 40+ countries, with the operation still live. Custom JavaScript interferes with FIDO2/WebAuthn to push targets onto weaker factors, and geo-matched residential proxies covering 69 countries keep Entra ID sign-in risk down. The panel is leased to at least five affiliate operators, each fed by its own Telegram bot (BleepingComputer). · Cloud & Identity

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited