<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 🪟 Windows Tipps]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=1&q=2FA]]></link> 
<description><![CDATA[Willkommen bei Windows Tipps, Ihrem Informationsportal für alles, was mit Windows zu tun hat. Hier finden Sie die neuesten Nachrichten, Tipps und Tricks, Downloads, Sicherheitswarnungen und mehr rund um Windows 11, Windows 10, Windows Server und andere Windows-Versionen. Egal, ob Sie ein Anfänger oder ein Profi sind, hier finden Sie nützliche Informationen, die Ihnen helfen, das Beste aus Ihrem Windows-System herauszuholen. Außerdem können Sie mit unserem Copilot-Feature schnell und einfach Produkte auf Microsoft Shopping finden. Schauen Sie sich unsere RSS-Feeds an, um immer auf dem Laufenden zu bleiben.]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=1&amp;q=2FA" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[A "critical" Microsoft Copilot exploit exposes AI gullibility — turning the chatbot into a data snitch for 2FA codes and sensitive emails]]></title> 
<description><![CDATA[Critical Copilot vulnerability lets hackers turn URLs into email‑search commands, leaking 2FA codes and enterprise data via Bing. ]]></description>
<link>https://tsecurity.de/de/3604937/IT+Betriebssysteme/Windows+Tipps/A+%22critical%22+Microsoft+Copilot+exploit+exposes+AI+gullibility+%E2%80%94+turning+the+chatbot+into+a+data+snitch+for+2FA+codes+and+sensitive+emails/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604937/IT+Betriebssysteme/Windows+Tipps/A+%22critical%22+Microsoft+Copilot+exploit+exposes+AI+gullibility+%E2%80%94+turning+the+chatbot+into+a+data+snitch+for+2FA+codes+and+sensitive+emails/</guid>
<pubDate>Wed, 17 Jun 2026 15:11:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes]]></title> 
<description><![CDATA[A state-linked hacker group known as Ghostwriter has launched a wave of targeted phishing attacks aimed at Gmail users, disguising malicious emails as official security alerts from Google. The campaign is designed to trick recipients into handing over their login&hellip;
Read more &rarr;
The post Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3603469/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+Hackers+Abuse+Gmail+Admin-Themed+Emails+to+Steal+Credentials+and+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603469/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+Hackers+Abuse+Gmail+Admin-Themed+Emails+to+Steal+Credentials+and+2FA+Codes/</guid>
<pubDate>Wed, 17 Jun 2026 04:09:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes]]></title> 
<description><![CDATA[A state-linked hacker group known as Ghostwriter has launched a wave of targeted phishing attacks aimed at Gmail users, disguising malicious emails as official security alerts from Google. The campaign is designed to trick recipients into handing over their login credentials and two-factor authentication codes, effectively bypassing one of the most trusted layers of account [&hellip;]
The post Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3603376/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+Hackers+Abuse+Gmail+Admin-Themed+Emails+to+Steal+Credentials+and+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603376/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+Hackers+Abuse+Gmail+Admin-Themed+Emails+to+Steal+Credentials+and+2FA+Codes/</guid>
<pubDate>Wed, 17 Jun 2026 02:08:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Copilot vulnerability allowed hackers to seal 2FA code from users]]></title> 
<description><![CDATA[SearchLeak exploit shows why the industry&#039;s approach to LLM security fails over and over. ]]></description>
<link>https://tsecurity.de/de/3601598/K%C3%BCnstliche+Intelligenz++Videos+%2F+AI/Critical+Copilot+vulnerability+allowed+hackers+to+seal+2FA+code+from+users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601598/K%C3%BCnstliche+Intelligenz++Videos+%2F+AI/Critical+Copilot+vulnerability+allowed+hackers+to+seal+2FA+code+from+users/</guid>
<pubDate>Tue, 16 Jun 2026 13:15:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes]]></title> 
<description><![CDATA[Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes, CERT Polska reports. The group historically focused on Polish email providers such as Onet, Wirtualna Polska&hellip;
Read more &rarr;
The post Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3601478/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+APT+Uses+Fake+Gmail+Login+Panels+to+Steal+Passwords+and+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601478/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+APT+Uses+Fake+Gmail+Login+Panels+to+Steal+Passwords+and+2FA+Codes/</guid>
<pubDate>Tue, 16 Jun 2026 12:32:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes]]></title> 
<description><![CDATA[Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes, CERT Polska reports. The group historically focused on Polish email providers such as Onet, Wirtualna Polska and Interia shifted in March 2026 to high-volume Gmail-targeted campaigns. Attackers send professionally worded Polish-language [&hellip;]
The post Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3601444/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+APT+Uses+Fake+Gmail+Login+Panels+to+Steal+Passwords+and+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601444/IT+Sicherheit/Cybersecurity+Nachrichten/Ghostwriter+APT+Uses+Fake+Gmail+Login+Panels+to+Steal+Passwords+and+2FA+Codes/</guid>
<pubDate>Tue, 16 Jun 2026 12:09:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[UNC1151 Ghostwriter Hackers Target Gmail Users With 2FA-Stealing Phishing Campaign]]></title> 
<description><![CDATA[The advanced persistent threat (APT) group UNC1151, widely tracked under the alias Ghostwriter, has significantly escalated its cyber espionage operations. Traditionally known for targeting regional Polish email providers like Onet, Wirtualna Polska, and Interia, the state-sponsored threat actors have abruptly shifted their focus. Since March 2026, the group has launched highly intensive phishing campaigns specifically [&hellip;]
The post UNC1151 Ghostwriter Hackers Target Gmail Users With 2FA-Stealing Phishing Campaign appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3601151/IT+Sicherheit/Cybersecurity+Nachrichten/UNC1151+Ghostwriter+Hackers+Target+Gmail+Users+With+2FA-Stealing+Phishing+Campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601151/IT+Sicherheit/Cybersecurity+Nachrichten/UNC1151+Ghostwriter+Hackers+Target+Gmail+Users+With+2FA-Stealing+Phishing+Campaign/</guid>
<pubDate>Tue, 16 Jun 2026 10:41:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes]]></title> 
<description><![CDATA[The UNC1151 Gmail phishing campaign has emerged as a cyber threat targeting Polish internet users, with attackers now focusing on Gmail accounts and deploying phishing pages capable of stealing both passwords and two-factor authentication (2FA) credentials. According to researchers at CERT Polska, the campaign marks a notable evolution in the tactics of the Ghostwriter-linked threat group, which has spent years targeting email users across Poland.

Also tracked as Ghostwriter and Storm-0257, UNC1151 has been linked by cybersecurity researchers to Belarusian state intelligence services and has remained active against Polish targets since Russia&#039;s full-scale invasion of Ukraine.
UNC1151 Gmail Phishing Campaign Expands Target Scope
For years, UNC1151 primarily targeted users of popular Polish email providers including Onetpasswords, Wirtualna Polska, and Interia. Since March 2026, however, the group has shifted its attention to Gmail users, launching high-volume phishing operations that run almost daily during weekdays.

CERT Polska researchers said the attackers target a wide range of individuals, including politicians, public officials, researchers, journalists, law enforcement personnel, government employees, and people connected to them through professional, family, or social relationships.

[caption id=&quot;attachment_112742&quot; align=&quot;aligncenter&quot; width=&quot;600&quot;] Image Source: CERT Polska[/caption]

The group also conducts campaigns against specific professional sectors and geographic regions. In some cases, phishing emails are sent to unintended recipients because attackers attempt to guess email addresses based on names and affiliations.
How the UNC1151 Gmail Phishing Campaign Works
The UNC1151 Gmail phishing campaign relies on fraudulent emails designed to resemble official Gmail security notifications. The messages often warn recipients about suspicious account activity, unauthorized login attempts, or alleged violations of service policies.

Victims are urged to act quickly to avoid account suspension or permanent deletion.

The emails are typically sent from Gmail accounts created specifically for phishing operations, although attackers occasionally use compromised accounts to increase credibility. Common subject lines include warnings about security alerts, suspicious activity, and account verification requirements.

Embedded links direct recipients to fake Gmail login pages that closely imitate Google&#039;s legitimate authentication portal. Once users enter their credentials, attackers capture both usernames and passwords.
2FA Credential Theft Marks Key Evolution
One of the most concerning developments in the campaign is its ability to harvest two-factor authentication theft credentials.

Unlike earlier phishing campaigns targeting Polish email services, the latest operation includes additional prompts requesting verification codes after login credentials have been entered. If a victim&#039;s account is protected by 2FA, the phishing page automatically displays a form requesting the authentication code.

This enables attackers to steal both SMS-based verification codes and codes generated through applications such as Google Authenticator.

Researchers noted that attackers frequently continue targeting the same victims even after unsuccessful login attempts. Multiple phishing emails may be delivered within days to increase pressure and improve the chances of credential theft.

[caption id=&quot;attachment_112735&quot; align=&quot;aligncenter&quot; width=&quot;600&quot;] Source: CERT Polska[/caption]
Ghostwriter Phishing Infrastructure Continues to Evolve
The campaign relies on a constantly changing phishing infrastructure.

According to CERT Polska, operators use domains registered specifically for phishing activities, often leveraging top-level domains such as .icu, .digital, and .top. The group also abuses hosting platforms such as Netlify by creating deceptive subdomains that imitate account verification services.

Examples of domains observed in the campaign include mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app, and service-auth.netlify.app.

In addition, attackers host fake login panels on compromised websites belonging to legitimate organizations. Rather than replacing the main website, the phishing content is hidden within the compromised infrastructure, allowing attacks to remain undetected for extended periods.
Gmail Phishing Attacks Signal Broader Threat
Security researchers warn that the increase in Gmail phishing attacks demonstrates UNC1151&#039;s continued ability to adapt its tactics while maintaining its long-standing objective of gaining access to email accounts.

Once access is obtained, attackers search for sensitive documents, contact lists, and linked services, including social media accounts that can be further compromised. Stolen contacts may also be used to identify additional targets for future phishing campaigns.

Although the group&#039;s recent focus has shifted toward Gmail, researchers caution that attacks against users of Polish email providers have not disappeared entirely.

The findings highlight the growing sophistication of state-linked phishing operations and reinforce the importance of scrutinizing login requests, verifying website domains, and protecting accounts with strong authentication practices.

As the UNC1151 Gmail phishing campaign continues to evolve, cybersecurity experts expect further adaptations designed to bypass defenses and increase the success rate of credential theft operations. ]]></description>
<link>https://tsecurity.de/de/3600994/IT+Sicherheit/Cybersecurity+Nachrichten/Belarus-Linked+UNC1151+Launches+Gmail+Phishing+Campaign+to+Steal+2FA+Codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600994/IT+Sicherheit/Cybersecurity+Nachrichten/Belarus-Linked+UNC1151+Launches+Gmail+Phishing+Campaign+to+Steal+2FA+Codes/</guid>
<pubDate>Tue, 16 Jun 2026 09:38:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/8414e35518f93e2b48ebc594de2faba51dbeca83: Preserve signed zero in FX complex codegen (#185550)]]></title> 
<description><![CDATA[FX codegen used complex.repr when rendering complex constants into generated Python source. CPython can print zero-component values such as (-0-1e-28j), -1e-28j, or (1-0j), and parsing that source can flip the sign of a zero component. Dynamo exposes this when it traces a tensor constant containing -1e-28j through FX: the generated GraphModule reconstructs a value with the wrong signed zero, changing tensor repr and the sign of the zero imaginary result from cos().
Render complex constants with a zero real or imaginary component as complex(real, imag) through the existing recursive argument printer. Float repr preserves -0.0, so those generated constants round-trip signed zero components. Nonzero complex constants keep the existing repr() path to avoid changing the common codegen case.
Fixes #153852
Generated by my agent
Benchmark Results:


FX GraphModule construction with 1000 zero-component complex constants, 80 iterations x 7 repeats, median: main 3.55 ms/graph; this diff 6.77 ms/graph. This is the affected correctness path that now emits complex(real, imag) to preserve signed zero.


FX GraphModule construction with 1000 nonzero complex constants, same command shape, median: main 4.29 ms/graph; this diff 3.90 ms/graph. Nonzero constants remain on the existing repr() path; the difference is measurement noise.


Test Plan:


python test/dynamo/test_repros.py ReproTests.test_compile_complex_tensor_constant_signed_zero


python test/test_fx.py TestFX.test_complex_constant_codegen_preserves_signed_zero (direct run blocked locally before target test by unrelated torchvision::nms registration failure)


targeted TestFX.test_complex_constant_codegen_preserves_signed_zero via a torchvision import stub


lintrunner -a


git diff --check


Pull Request resolved: #185550
Approved by: https://github.com/desertfire ]]></description>
<link>https://tsecurity.de/de/3599609/IT+Downloads/trunk%2F8414e35518f93e2b48ebc594de2faba51dbeca83%3A+Preserve+signed+zero+in+FX+complex+codegen+%28%23185550%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599609/IT+Downloads/trunk%2F8414e35518f93e2b48ebc594de2faba51dbeca83%3A+Preserve+signed+zero+in+FX+complex+codegen+%28%23185550%29/</guid>
<pubDate>Mon, 15 Jun 2026 17:22:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/29dbb32fa190890a7c746412ec1eb5bcde336244]]></title> 
<description><![CDATA[[Inductor][xpu] Support bmg-g31 arch compilation for sycl-tla backend&hellip; ]]></description>
<link>https://tsecurity.de/de/3596818/IT+Downloads/trunk%2F29dbb32fa190890a7c746412ec1eb5bcde336244/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596818/IT+Downloads/trunk%2F29dbb32fa190890a7c746412ec1eb5bcde336244/</guid>
<pubDate>Sun, 14 Jun 2026 11:02:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/19afbb4e2e81cc5702fa8cc34c48e1879b98a5aa: [c++20] Simplify waiting using std::latch (#187194)]]></title> 
<description><![CDATA[This commit updates ParallelNative to use a single std::latch (C++20) in place of an atomic + mutex + condvar. #176662.
Pull Request resolved: #187194
Approved by: https://github.com/Skylion007 ]]></description>
<link>https://tsecurity.de/de/3594793/IT+Downloads/trunk%2F19afbb4e2e81cc5702fa8cc34c48e1879b98a5aa%3A+%5Bc%2B%2B20%5D+Simplify+waiting+using+std%3A%3Alatch+%28%23187194%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594793/IT+Downloads/trunk%2F19afbb4e2e81cc5702fa8cc34c48e1879b98a5aa%3A+%5Bc%2B%2B20%5D+Simplify+waiting+using+std%3A%3Alatch+%28%23187194%29/</guid>
<pubDate>Sat, 13 Jun 2026 02:42:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/a4097e577fe5d1e21dfe2fa8c36af3fdf8854e34: Revert "[BE] Make spmd_type a CI rather than CD dependency (#187067)"]]></title> 
<description><![CDATA[This reverts commit d4c98cd.
Reverted #187067 on behalf of https://github.com/pytorch-auto-revert due to Reverted automatically by pytorch&#039;s autorevert, to avoid this behaviour add the tag autorevert: disable (comment) ]]></description>
<link>https://tsecurity.de/de/3592173/IT+Downloads/trunk%2Fa4097e577fe5d1e21dfe2fa8c36af3fdf8854e34%3A+Revert+%26quot%3B%5BBE%5D+Make+spmd_type+a+CI+rather+than+CD+dependency+%28%23187067%29%26quot%3B/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592173/IT+Downloads/trunk%2Fa4097e577fe5d1e21dfe2fa8c36af3fdf8854e34%3A+Revert+%26quot%3B%5BBE%5D+Make+spmd_type+a+CI+rather+than+CD+dependency+%28%23187067%29%26quot%3B/</guid>
<pubDate>Fri, 12 Jun 2026 03:03:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Industry Perspective by Cloudflare: Dismantling Tycoon 2FA, Inside a Global Phishing Takedown]]></title> 
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:0 CyCon 2026 |  Session by Michiel Appelman, Principal Solutions Engineer, Cloudflare

In March 2026, Cloudflare coordinated with Microsoft and Europol to dismantle Tycoon 2FA, one of the most widely used phishing-as-a-service platforms. For $120 a month, any criminal could subscribe. The operation took down 24,000 domains and the serverless infrastructure that let the kit proxy live authentication sessions. Multi-factor authentication was useless against it.

This session uses the takedown as a lens into broader shifts in adversary operations. Tycoon 2FA did not succeed through technical sophistication. It succeeded because it&#039;s optimized for what Cloudflare&#039;s threat intelligence team calls the &quot;Measure of Effectiveness&quot; - the ratio of effort to outcome. The same logic explains why Chinese state actors now route command-and-control through Google Calendar, why session token theft has overtaken zero-day exploits as the primary access method, and why nation-state groups are pre-positioning inside critical infrastructure using tools that look identical to normal enterprise traffic.

#CCDCOE #CyCon2026 ]]></description>
<link>https://tsecurity.de/de/3585457/IT+Sicherheit/Cybersecurity+Videos/Industry+Perspective+by+Cloudflare%3A+Dismantling+Tycoon+2FA%2C+Inside+a+Global+Phishing+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585457/IT+Sicherheit/Cybersecurity+Videos/Industry+Perspective+by+Cloudflare%3A+Dismantling+Tycoon+2FA%2C+Inside+a+Global+Phishing+Takedown/</guid>
<pubDate>Tue, 09 Jun 2026 19:36:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-31514 | Fortinet FortiProxy/FortiOS 2FA log file (FG-IR-24-452 / Nessus ID 270400)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Fortinet FortiProxy and FortiOS. Impacted is an unknown function of the component 2FA. Executing a manipulation can lead to sensitive information in log files.

This vulnerability is registered as CVE-2025-31514. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3585287/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-31514+%7C+Fortinet+FortiProxy%2FFortiOS+2FA+log+file+%28FG-IR-24-452+%2F+Nessus+ID+270400%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585287/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-31514+%7C+Fortinet+FortiProxy%2FFortiOS+2FA+log+file+%28FG-IR-24-452+%2F+Nessus+ID+270400%29/</guid>
<pubDate>Tue, 09 Jun 2026 19:02:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Dashlane-Angriff: Hacker knackten 2FA-Codes per Brute-Force - Ad-hoc-news.de]]></title> 
<description><![CDATA[Hacker erbeuten durch Brute-Force-Angriff auf API verschl&uuml;sselte Tresore von weniger als 20 Dashlane-Nutzern. ]]></description>
<link>https://tsecurity.de/de/3577565/IT+Sicherheit/Hacker/Dashlane-Angriff%3A+Hacker+knackten+2FA-Codes+per+Brute-Force+-+Ad-hoc-news.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577565/IT+Sicherheit/Hacker/Dashlane-Angriff%3A+Hacker+knackten+2FA-Codes+per+Brute-Force+-+Ad-hoc-news.de/</guid>
<pubDate>Sat, 06 Jun 2026 09:25:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Dashlane-Attacke: Hacker umgehen 2FA, erbeuten 20 Passwort-Tresore - Ad-hoc-news.de]]></title> 
<description><![CDATA[Hacker umgehen Dashlanes 2FA und stehlen verschl&uuml;sselte Tresore. Die Zero-Knowledge-Architektur verhindert jedoch die Entschl&uuml;sselung der Daten. ]]></description>
<link>https://tsecurity.de/de/3577564/IT+Sicherheit/Hacker/Dashlane-Attacke%3A+Hacker+umgehen+2FA%2C+erbeuten+20+Passwort-Tresore+-+Ad-hoc-news.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577564/IT+Sicherheit/Hacker/Dashlane-Attacke%3A+Hacker+umgehen+2FA%2C+erbeuten+20+Passwort-Tresore+-+Ad-hoc-news.de/</guid>
<pubDate>Sat, 06 Jun 2026 09:27:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/ae97c9f9a57145ec0d71543d08362fa1d476fff0: [Full DTensor][FSDP] Use _StridedShard when TP exist (#186126)]]></title> 
<description><![CDATA[Same as the non-full-dtensor path, we have to use _StridedShard to ensure the correctness of resharding.
Pull Request resolved: #186126
Approved by: https://github.com/pianpwk, https://github.com/weifengpy ]]></description>
<link>https://tsecurity.de/de/3574243/IT+Downloads/trunk%2Fae97c9f9a57145ec0d71543d08362fa1d476fff0%3A+%5BFull+DTensor%5D%5BFSDP%5D+Use+_StridedShard+when+TP+exist+%28%23186126%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574243/IT+Downloads/trunk%2Fae97c9f9a57145ec0d71543d08362fa1d476fff0%3A+%5BFull+DTensor%5D%5BFSDP%5D+Use+_StridedShard+when+TP+exist+%28%23186126%29/</guid>
<pubDate>Fri, 05 Jun 2026 04:16:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Dashlane meldet Brute-Force auf 2FA: Zugriff auf ]]></title> 
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) &ndash; Dashlane warnt vor einem Brute-Force-Angriff, der auf bestimmte Nutzerkonten abzielte und versucht hat, 2FA-Schutzmechanismen zu umgehen. In wenigen F&auml;llen konnten Angreifer auf verschl&uuml;sselte Vault-Daten zugreifen und diese herunterladen, wie der Passwortmanager nun &ouml;ffentlich macht. Betroffene Nutzer wurden direkt informiert, gleichzeitig betont Dashlane, dass Master-Passw&ouml;rter weiterhin Voraussetzung f&uuml;r jede Entschl&uuml;sselung [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Dashlane meldet Brute-Force auf 2FA: Zugriff auf  ]]></description>
<link>https://tsecurity.de/de/3572251/IT+Sicherheit/Cybersecurity+Nachrichten/Dashlane+meldet+Brute-Force+auf+2FA%3A+Zugriff+auf+%26lt%3B20+verschl%C3%BCsselte+Vaults/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572251/IT+Sicherheit/Cybersecurity+Nachrichten/Dashlane+meldet+Brute-Force+auf+2FA%3A+Zugriff+auf+%26lt%3B20+verschl%C3%BCsselte+Vaults/</guid>
<pubDate>Thu, 04 Jun 2026 12:50:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Kali365: Hacker umgehen 2FA in Microsoft-365-Umgebungen - BornCity]]></title> 
<description><![CDATA[Hacker umgehen Zwei-Faktor-Authentifizierung mit immer raffinierteren Methoden. Besonders betroffen: Microsoft-365-Nutzer. Die Bedrohungslage in&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3571518/IT+Sicherheit/Hacker/Kali365%3A+Hacker+umgehen+2FA+in+Microsoft-365-Umgebungen+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571518/IT+Sicherheit/Hacker/Kali365%3A+Hacker+umgehen+2FA+in+Microsoft-365-Umgebungen+-+BornCity/</guid>
<pubDate>Thu, 04 Jun 2026 04:25:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA]]></title> 
<description><![CDATA[      A reported flaw in Meta&rsquo;s AI-powered Instagram recovery flow allegedly let attackers trigger password reset emails and bypass 2FA by convincing the AI assistant to act on their behalf. The issue is less about &ldquo;AI being smart&rdquo; and more about poor privilege boundaries: an AI agent had access to sensitive account-recovery actions without a hard authentication checkpoint.    submitted by    /u/raptorhunter22   [link]   [comments]  ]]></description>
<link>https://tsecurity.de/de/3564712/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+AI+Password+Reset+Flaw+Reportedly+Bypassed+Instagram+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564712/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+AI+Password+Reset+Flaw+Reportedly+Bypassed+Instagram+2FA/</guid>
<pubDate>Mon, 01 Jun 2026 07:08:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Meta patches flaw that allowed MetaAI support bot to hand out password reset links without 2FA]]></title> 
<description><![CDATA[Hackers were targeting high-profile accounts by tricking AI into sharing reset codes without validation. ]]></description>
<link>https://tsecurity.de/de/3562973/IT+Nachrichten/Meta+patches+flaw+that+allowed+MetaAI+support+bot+to+hand+out+password+reset+links+without+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562973/IT+Nachrichten/Meta+patches+flaw+that+allowed+MetaAI+support+bot+to+hand+out+password+reset+links+without+2FA/</guid>
<pubDate>Mon, 01 Jun 2026 14:05:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/164855bb6a8e8708551338a9ee5c2fa23f2709b0: Fix AOT FXIR parallel Triton kernel reload (#185134)]]></title> 
<description><![CDATA[AOT FXIR imports generated Triton kernels through the wrapper code and then stores the JITFunction in the Triton HOP side table. With parallel Triton compile enabled, the worker returns a pickled CachingAutotuner whose JITFunction has had its underlying Python function stripped by prepare_for_pickle(). FXIR then registered that stripped JITFunction, so a fresh runtime compile could reach Triton&#039;s source-location lookup and fail with AttributeError because fn.fn was None.
Reload the parent-side JITFunction after resolving the async compile future and before FXIR wraps it for the side table. This keeps the root cause local to the FXIR import path that consumes worker-returned autotuners. The alternative of forcing compile_threads=1 avoids the race but leaves parallel compile broken, so the existing test workaround is not relied on.
Add a regression test that forces subprocess parallel compile with a fresh cache, checks the side-table kernel has a live function, and executes the generated FXIR graph.
Fixes #162607
Generated by my agent
Test Plan:
pytest -q test/inductor/test_fxir_backend.py -k &#039;test_aoti_fx_add or test_aoti_fx_parallel_compile_reloads_triton_kernel&#039;
lintrunner -a
Pull Request resolved: #185134
Approved by: https://github.com/angelayi ]]></description>
<link>https://tsecurity.de/de/3561695/IT+Downloads/trunk%2F164855bb6a8e8708551338a9ee5c2fa23f2709b0%3A+Fix+AOT+FXIR+parallel+Triton+kernel+reload+%28%23185134%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561695/IT+Downloads/trunk%2F164855bb6a8e8708551338a9ee5c2fa23f2709b0%3A+Fix+AOT+FXIR+parallel+Triton+kernel+reload+%28%23185134%29/</guid>
<pubDate>Mon, 01 Jun 2026 04:19:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-2891 | WP 2FA Plugin up to 2.2.x on WordPress Authentication Code timing discrepancy (EUVD-2022-35120)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in WP 2FA Plugin up to 2.2.x on WordPress. Affected by this issue is some unknown functionality of the component Authentication Code Handler. Performing a manipulation results in observable timing discrepancy.

This vulnerability is reported as CVE-2022-2891. The attacker must have access to the local network to execute the attack. No exploit exists.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3552782/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-2891+%7C+WP+2FA+Plugin+up+to+2.2.x+on+WordPress+Authentication+Code+timing+discrepancy+%28EUVD-2022-35120%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552782/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-2891+%7C+WP+2FA+Plugin+up+to+2.2.x+on+WordPress+Authentication+Code+timing+discrepancy+%28EUVD-2022-35120%29/</guid>
<pubDate>Thu, 28 May 2026 03:32:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/fd6d216e3e8bf07c470716dfbf022d82fadd521d: Fix slow_conv_dilated3d non-batched output indexing (#185352)]]></title> 
<description><![CDATA[Fix a silent-corruption / out-of-bounds bug in slow_conv_dilated3d (CUDA and CPU)
when called with non-batched 4D input and a defined bias.
Pull Request resolved: #185352
Approved by: https://github.com/Skylion007 ]]></description>
<link>https://tsecurity.de/de/3552737/IT+Downloads/trunk%2Ffd6d216e3e8bf07c470716dfbf022d82fadd521d%3A+Fix+slow_conv_dilated3d+non-batched+output+indexing+%28%23185352%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552737/IT+Downloads/trunk%2Ffd6d216e3e8bf07c470716dfbf022d82fadd521d%3A+Fix+slow_conv_dilated3d+non-batched+output+indexing+%28%23185352%29/</guid>
<pubDate>Thu, 28 May 2026 02:48:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48896 | Joomla CMS up to 5.4.5/6.1.0 2FA improper authentication (WID-SEC-2026-1688)]]></title> 
<description><![CDATA[A vulnerability has been found in Joomla CMS up to 5.4.5/6.1.0 and classified as critical. This affects an unknown function of the component 2FA. This manipulation causes improper authentication.

This vulnerability is registered as CVE-2026-48896. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3552364/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48896+%7C+Joomla+CMS+up+to+5.4.5%2F6.1.0+2FA+improper+authentication+%28WID-SEC-2026-1688%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552364/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48896+%7C+Joomla+CMS+up+to+5.4.5%2F6.1.0+2FA+improper+authentication+%28WID-SEC-2026-1688%29/</guid>
<pubDate>Wed, 27 May 2026 21:46:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48897 | Joomla CMS up to 5.4.5/6.1.0 2FA improper authentication (WID-SEC-2026-1688)]]></title> 
<description><![CDATA[A vulnerability was found in Joomla CMS up to 5.4.5/6.1.0 and classified as critical. This impacts an unknown function of the component 2FA. Such manipulation leads to improper authentication.

This vulnerability is documented as CVE-2026-48897. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3552363/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48897+%7C+Joomla+CMS+up+to+5.4.5%2F6.1.0+2FA+improper+authentication+%28WID-SEC-2026-1688%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552363/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48897+%7C+Joomla+CMS+up+to+5.4.5%2F6.1.0+2FA+improper+authentication+%28WID-SEC-2026-1688%29/</guid>
<pubDate>Wed, 27 May 2026 21:46:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts]]></title> 
<description><![CDATA[A powerful phishing kit known as Tycoon 2FA has been making waves across the cybersecurity world since it first appeared in August 2023. The kit operates as a Phishing-as-a-Service (PhaaS) platform, meaning cybercriminals can rent and deploy it without building&hellip;
Read more &rarr;
The post Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3552294/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Bypasses+MFA+on+Entra+ID+and+Google+Workspace+Accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552294/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Bypasses+MFA+on+Entra+ID+and+Google+Workspace+Accounts/</guid>
<pubDate>Wed, 27 May 2026 21:34:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts]]></title> 
<description><![CDATA[A powerful phishing kit known as Tycoon 2FA has been making waves across the cybersecurity world since it first appeared in August 2023. The kit operates as a Phishing-as-a-Service (PhaaS) platform, meaning cybercriminals can rent and deploy it without building anything from scratch. Its primary goal is to steal authenticated session tokens from Microsoft 365 [&hellip;]
The post Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3552197/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Bypasses+MFA+on+Entra+ID+and+Google+Workspace+Accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552197/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Bypasses+MFA+on+Entra+ID+and+Google+Workspace+Accounts/</guid>
<pubDate>Wed, 27 May 2026 20:50:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[npm führt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; npm bekommt mit staged publishing ein neues Kontrollmodell: Maintainer laden Pakete zun&auml;chst in eine Stage-Queue hoch und m&uuml;ssen dann per 2FA manuell freigeben, bevor Versionen installierbar werden. Damit schafft GitHub nach dem Prinzip &bdquo;proof of presence&ldquo; eine zus&auml;tzliche H&uuml;rde gegen automatisierte Manipulationen aus kompromittierten Accounts oder fehlerhaften CI/CD-Pipelines. Die Umstellung ist [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;npm f&uuml;hrt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes&laquo; lesen
Dieser Beitrag npm f&uuml;hrt staged publishing ein: 2FA-Freigabe stoppt riskante Supply-Chain-Publishes erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3551770/IT+Sicherheit/Cybersecurity+Nachrichten/npm+f%C3%BChrt+staged+publishing+ein%3A+2FA-Freigabe+stoppt+riskante+Supply-Chain-Publishes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551770/IT+Sicherheit/Cybersecurity+Nachrichten/npm+f%C3%BChrt+staged+publishing+ein%3A+2FA-Freigabe+stoppt+riskante+Supply-Chain-Publishes/</guid>
<pubDate>Wed, 27 May 2026 18:05:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA AiTM Kit Targets Entra ID and Google Workspace In MFA Bypass Campaigns]]></title> 
<description><![CDATA[The notorious Tycoon 2FA Phishing-as-a-Service (PhaaS) platform is back, proving that even a global law enforcement takedown cannot keep cybercriminals offline for long. Originally attributed to the threat actor Storm-1747, this adversary-in-the-middle (AiTM) kit specializes in bypassing multi-factor authentication (MFA) for Microsoft 365 and Google Workspace accounts. Despite a massive coordinated disruption by Microsoft and [&hellip;]
The post Tycoon 2FA AiTM Kit Targets Entra ID and Google Workspace In MFA Bypass Campaigns appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3550631/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Targets+Entra+ID+and+Google+Workspace+In+MFA+Bypass+Campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550631/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+AiTM+Kit+Targets+Entra+ID+and+Google+Workspace+In+MFA+Bypass+Campaigns/</guid>
<pubDate>Wed, 27 May 2026 11:59:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft 365: KI entwickelt ersten Zero-Day-Exploit gegen 2FA - BornCity]]></title> 
<description><![CDATA[Hacker umgehen Zwei-Faktor-Authentifizierung &ndash; KI entwickelt erstmals eigenen Exploit gegen 2FA. Die Sicherheitslage f&uuml;r Unternehmen, die auf&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3550152/IT+Sicherheit/Hacker/Microsoft+365%3A+KI+entwickelt+ersten+Zero-Day-Exploit+gegen+2FA+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550152/IT+Sicherheit/Hacker/Microsoft+365%3A+KI+entwickelt+ersten+Zero-Day-Exploit+gegen+2FA+-+BornCity/</guid>
<pubDate>Wed, 27 May 2026 01:35:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PlayStation-Hacking: Social Engineering hebelt 2FA und Passkeys aus - Ad-hoc-news.de]]></title> 
<description><![CDATA[Soziale Manipulation statt Hacking: Angreifer nutzen menschliche Schwachstelle im PlayStation-Support aus. Schwerwiegende Sicherheitsl&uuml;cken im&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3549058/IT+Sicherheit/Hacker/PlayStation-Hacking%3A+Social+Engineering+hebelt+2FA+und+Passkeys+aus+-+Ad-hoc-news.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549058/IT+Sicherheit/Hacker/PlayStation-Hacking%3A+Social+Engineering+hebelt+2FA+und+Passkeys+aus+-+Ad-hoc-news.de/</guid>
<pubDate>Tue, 26 May 2026 17:33:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace]]></title> 
<description><![CDATA[Tycoon 2FA bypasses MFA on Entra ID and Google Workspace. We map telemetry fingerprints across both platforms, ship detection rules for both tiers, and contain incidents in under 10 seconds with Elastic Workflows. ]]></description>
<link>https://tsecurity.de/de/3548776/IT+Sicherheit/Cybersecurity+Nachrichten/Detecting+Tycoon+2FA+AiTM+attacks+across+Entra+ID+and+Google+Workspace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548776/IT+Sicherheit/Cybersecurity+Nachrichten/Detecting+Tycoon+2FA+AiTM+attacks+across+Entra+ID+and+Google+Workspace/</guid>
<pubDate>Tue, 26 May 2026 02:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[I need help bypassing the snapchat 2fa please]]></title> 
<description><![CDATA[I need to find a Way to bypass either the snapchat or the Gmail 2fa and i can&rsquo;t seem to if anyone could help please it is to recover an account     submitted by    /u/Euphoric-Ad9802   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3546500/IT+Sicherheit/Cybersecurity+Nachrichten/I+need+help+bypassing+the+snapchat+2fa+please/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546500/IT+Sicherheit/Cybersecurity+Nachrichten/I+need+help+bypassing+the+snapchat+2fa+please/</guid>
<pubDate>Thu, 21 May 2026 03:01:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft Warns Passwords and SMS-Based 2FA Are No Longer Enough Against Modern Cyberattacks]]></title> 
<description><![CDATA[Microsoft is intensifying its push toward passwordless security, warning that traditional passwords and older forms of two-factor authentication are becoming increasingly ineffective against modern phishing attacks powered by artificial intelligence. In a statement released during World Passkey Day, Microsoft said&hellip;
Read more &rarr;
The post Microsoft Warns Passwords and SMS-Based 2FA Are No Longer Enough Against Modern Cyberattacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3545237/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+Warns+Passwords+and+SMS-Based+2FA+Are+No+Longer+Enough+Against+Modern+Cyberattacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545237/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+Warns+Passwords+and+SMS-Based+2FA+Are+No+Longer+Enough+Against+Modern+Cyberattacks/</guid>
<pubDate>Mon, 25 May 2026 11:34:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[npm führt staged publishing ein: 2FA-Freigabe vor Paket-Installation]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; GitHub macht npm-Deployments sicherer: Mit &bdquo;staged publishing&ldquo; m&uuml;ssen Maintainer eine 2FA-Pflichtaktion ausf&uuml;hren, bevor ein Paket &ouml;ffentlich installierbar wird. Zus&auml;tzlich erg&auml;nzt npm gezielte Install-Quellen-Flags, die Nicht-Registry-Quellen besser kontrollierbar machen. Die &Auml;nderungen kommen in einer Phase steigender Angriffe auf Open-Source-&Ouml;kosysteme und richten sich besonders an CI/CD-Workflows, die bisher unbemerkt kompromittiert werden konnten. Wer [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;npm f&uuml;hrt staged publishing ein: 2FA-Freigabe vor Paket-Installation&laquo; lesen
Dieser Beitrag npm f&uuml;hrt staged publishing ein: 2FA-Freigabe vor Paket-Installation erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3544333/IT+Sicherheit/Cybersecurity+Nachrichten/npm+f%C3%BChrt+staged+publishing+ein%3A+2FA-Freigabe+vor+Paket-Installation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544333/IT+Sicherheit/Cybersecurity+Nachrichten/npm+f%C3%BChrt+staged+publishing+ein%3A+2FA-Freigabe+vor+Paket-Installation/</guid>
<pubDate>Mon, 25 May 2026 00:38:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks]]></title> 
<description><![CDATA[GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation.

Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve ]]></description>
<link>https://tsecurity.de/de/3542311/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Adds+2FA-Gated+Publishing+and+Package+Install+Controls+Against+Supply+Chain+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542311/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Adds+2FA-Gated+Publishing+and+Package+Install+Controls+Against+Supply+Chain+Attacks/</guid>
<pubDate>Sat, 23 May 2026 18:35:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks]]></title> 
<description><![CDATA[GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature&hellip;
Read more &rarr;
The post npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3542310/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Adds+2FA-Gated+Publishing+and+Package+Install+Controls+Against+Supply+Chain+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542310/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Adds+2FA-Gated+Publishing+and+Package+Install+Controls+Against+Supply+Chain+Attacks/</guid>
<pubDate>Sat, 23 May 2026 19:02:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PSN-Sicherheitslücke: Sony-Support hebelt selbst 2FA aus]]></title> 
<description><![CDATA[PSN-Sicherheitsl&uuml;cke sorgt f&uuml;r Alarm: Hacker kapern PlayStation-Accounts &uuml;ber Sonys Kundensupport. Selbst 2FA hilft nicht mehr.
Der Artikel PSN-Sicherheitsl&uuml;cke: Sony-Support hebelt selbst 2FA aus erschien zuerst auf TARNKAPPE.INFO ]]></description>
<link>https://tsecurity.de/de/3542170/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/PSN-Sicherheitsl%C3%BCcke%3A+Sony-Support+hebelt+selbst+2FA+aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542170/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/PSN-Sicherheitsl%C3%BCcke%3A+Sony-Support+hebelt+selbst+2FA+aus/</guid>
<pubDate>Sat, 23 May 2026 17:24:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/7659779cf2612f9182facf974da4ba6124d63bd8: [MPS] Validate stride > 0 in pool ops to match CPU behavior (#184875)]]></title> 
<description><![CDATA[Pull Request resolved: #184875
Approved by: https://github.com/malfet ]]></description>
<link>https://tsecurity.de/de/3539614/IT+Downloads/trunk%2F7659779cf2612f9182facf974da4ba6124d63bd8%3A+%5BMPS%5D+Validate+stride+%26gt%3B+0+in+pool+ops+to+match+CPU+behavior+%28%23184875%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539614/IT+Downloads/trunk%2F7659779cf2612f9182facf974da4ba6124d63bd8%3A+%5BMPS%5D+Validate+stride+%26gt%3B+0+in+pool+ops+to+match+CPU+behavior+%28%23184875%29/</guid>
<pubDate>Fri, 22 May 2026 14:46:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/609efe010dcde92fa56df05209102e43def23d28: Fix ZeroTensor view with symbolic sizes (#184651)]]></title> 
<description><![CDATA[Route ZeroTensor view metadata paths through SymInt-aware implementations so AOTAutograd can trace dynamic-shape group norm backward without concretizing sizes.
Fixes #181384
Generated by my agent
Pull Request resolved: #184651
Approved by: https://github.com/ezyang ]]></description>
<link>https://tsecurity.de/de/3538896/IT+Downloads/trunk%2F609efe010dcde92fa56df05209102e43def23d28%3A+Fix+ZeroTensor+view+with+symbolic+sizes+%28%23184651%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538896/IT+Downloads/trunk%2F609efe010dcde92fa56df05209102e43def23d28%3A+Fix+ZeroTensor+view+with+symbolic+sizes+%28%23184651%29/</guid>
<pubDate>Fri, 22 May 2026 10:46:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens]]></title> 
<description><![CDATA[The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of developers. On May 19, npm invalidated every granular access token with write access that bypasses two-factor authentication, forcing maintainers to generate fresh credentials&hellip;
Read more &rarr;
The post Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3538706/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Forces+npm+to+Reset+Bypass-2FA+Publishing+Tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538706/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Forces+npm+to+Reset+Bypass-2FA+Publishing+Tokens/</guid>
<pubDate>Fri, 22 May 2026 09:32:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens]]></title> 
<description><![CDATA[The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of developers. On May 19, npm invalidated every granular access token with write access that bypasses two-factor authentication, forcing maintainers to generate fresh credentials and update all automated workflows. The reset came directly in response to a campaign known [&hellip;]
The post Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3538582/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Forces+npm+to+Reset+Bypass-2FA+Publishing+Tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538582/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Forces+npm+to+Reset+Bypass-2FA+Publishing+Tokens/</guid>
<pubDate>Fri, 22 May 2026 08:24:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[npm Resets Bypass-2FA Tokens After Mini Shai-Hulud Supply Chain Attack]]></title> 
<description><![CDATA[npm has invalidated all granular write-access tokens that bypass two-factor authentication (2FA). This platform-wide credential reset, announced on May 19, 2026, aims to disrupt the massive &ldquo;Mini Shai-Hulud&rdquo; supply chain campaign that has heavily targeted the JavaScript ecosystem. Maintainers must now generate new tokens and update their continuous integration (CI) environments. The registry took this [&hellip;]
The post npm Resets Bypass-2FA Tokens After Mini Shai-Hulud Supply Chain Attack appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3538580/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Resets+Bypass-2FA+Tokens+After+Mini+Shai-Hulud+Supply+Chain+Attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538580/IT+Sicherheit/Cybersecurity+Nachrichten/npm+Resets+Bypass-2FA+Tokens+After+Mini+Shai-Hulud+Supply+Chain+Attack/</guid>
<pubDate>Fri, 22 May 2026 08:30:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens]]></title> 
<description><![CDATA[npm has forced a platform-wide reset of granular access tokens that bypass two-factor authentication (2FA) after a wave of supply chain attacks linked to the &ldquo;Mini Shai-Hulud&rdquo; campaign compromised hundreds of JavaScript packages. The emergency action, rolled out on May&hellip;
Read more &rarr;
The post Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3538449/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Prompts+npm+to+Revoke+2FA-Bypass+Tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538449/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Prompts+npm+to+Revoke+2FA-Bypass+Tokens/</guid>
<pubDate>Fri, 22 May 2026 07:32:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens]]></title> 
<description><![CDATA[npm has forced a platform-wide reset of granular access tokens that bypass two-factor authentication (2FA) after a wave of supply chain attacks linked to the &ldquo;Mini Shai-Hulud&rdquo; campaign compromised hundreds of JavaScript packages. The emergency action, rolled out on May 19, invalidated all npm tokens with write permissions that allowed publishing without 2FA. The move [&hellip;]
The post Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3538416/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Prompts+npm+to+Revoke+2FA-Bypass+Tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538416/IT+Sicherheit/Cybersecurity+Nachrichten/Mini+Shai-Hulud+Attack+Prompts+npm+to+Revoke+2FA-Bypass+Tokens/</guid>
<pubDate>Fri, 22 May 2026 07:07:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft Ditches SMS-Based 2FA Because It's Too Easy to Hack]]></title> 
<description><![CDATA[Users who currently rely on SMS for Microsoft login security will need to set up at least one alternative. ]]></description>
<link>https://tsecurity.de/de/3533733/IT+Nachrichten/Microsoft+Ditches+SMS-Based+2FA+Because+It%27s+Too+Easy+to+Hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533733/IT+Nachrichten/Microsoft+Ditches+SMS-Based+2FA+Because+It%27s+Too+Easy+to+Hack/</guid>
<pubDate>Wed, 20 May 2026 17:52:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Server-Admin-Tool: 2FA von Webmin umgehbar | heise online]]></title> 
<description><![CDATA[Das Admin-Tool f&uuml;r Unix-Server Webmin ist verwundbar. Angreifer k&ouml;nnen unter anderem die Zwei-Faktor-Authentifizierung (2FA) umgehen. Es sind aber&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3528408/IT+Server/Unix+Server/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528408/IT+Server/Unix+Server/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar+%7C+heise+online/</guid>
<pubDate>Tue, 19 May 2026 09:35:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Server Admin Tool: Webmin's 2FA bypassable | heise online]]></title> 
<description><![CDATA[The admin tool for Unix servers, Webmin, is vulnerable. Attackers can bypass two-factor authentication (2FA), among other things. However, root&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3528407/IT+Server/Unix+Server/Server+Admin+Tool%3A+Webmin%27s+2FA+bypassable+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528407/IT+Server/Unix+Server/Server+Admin+Tool%3A+Webmin%27s+2FA+bypassable+%7C+heise+online/</guid>
<pubDate>Tue, 19 May 2026 10:19:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Server-Admin-Tool: 2FA von Webmin umgehbar]]></title> 
<description><![CDATA[Webmin ist &uuml;ber mehrere Sicherheitsl&uuml;cken angreifbar. Neben 2FA- sind auch root-Attacken m&ouml;glich. Nun haben die Entwickler Sicherheitspatches ver&ouml;ffentlicht. ]]></description>
<link>https://tsecurity.de/de/3528187/IT+Nachrichten/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528187/IT+Nachrichten/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar/</guid>
<pubDate>Tue, 19 May 2026 09:28:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Server-Admin-Tool: 2FA von Webmin umgehbar]]></title> 
<description><![CDATA[Webmin ist &uuml;ber mehrere Sicherheitsl&uuml;cken angreifbar. Neben 2FA- sind auch root-Attacken m&ouml;glich. Nun haben die Entwickler Sicherheitspatches ver&ouml;ffentlicht. ]]></description>
<link>https://tsecurity.de/de/3528159/IT+Sicherheit/Cybersecurity+Nachrichten/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528159/IT+Sicherheit/Cybersecurity+Nachrichten/Server-Admin-Tool%3A+2FA+von+Webmin+umgehbar/</guid>
<pubDate>Tue, 19 May 2026 09:28:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Adopts OAuth Device Code Attacks In MFA Bypass Campaign]]></title> 
<description><![CDATA[Threat actors rarely stay down for long. Just weeks after a massive global takedown in March 2026, the notorious Tycoon 2FA Phishing-as-a-Service (PhaaS) kit has resurfaced with a dangerous new trick. Instead of stealing passwords, cybercriminals are now abusing Microsoft&rsquo;s OAuth Device Authorization Grant flow to bypass Multi-Factor Authentication (MFA) entirely. Security researchers at the [&hellip;]
The post Tycoon 2FA Adopts OAuth Device Code Attacks In MFA Bypass Campaign appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3524914/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Adopts+OAuth+Device+Code+Attacks+In+MFA+Bypass+Campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3524914/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Adopts+OAuth+Device+Code+Attacks+In+MFA+Bypass+Campaign/</guid>
<pubDate>Mon, 18 May 2026 07:37:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing]]></title> 
<description><![CDATA[The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. [...] ]]></description>
<link>https://tsecurity.de/de/3523903/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+hijacks+Microsoft+365+accounts+via+device-code+phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3523903/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+hijacks+Microsoft+365+accounts+via+device-code+phishing/</guid>
<pubDate>Sun, 17 May 2026 16:43:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA]]></title> 
<description><![CDATA[Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a&hellip;
Read more &rarr;
The post Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3519881/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Adopt+OAuth+Device+Code+Phishing+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519881/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Adopt+OAuth+Device+Code+Phishing+to+Bypass+MFA/</guid>
<pubDate>Fri, 15 May 2026 15:34:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Erster KI-entwickelter Zero-Day-Angriff auf 2FA-Systeme identifiziert]]></title> 
<description><![CDATA[
    Google meldet den ersten bekannten Einsatz von KI zur Entwicklung eines Zero-Day-Exploits. Betroffen sind 2FA-Mechanismen und Android-Systeme weltweit.

Tags: #Cyber Crime | #K&uuml;nstliche Intelligenz | #Zero Day ]]></description>
<link>https://tsecurity.de/de/3519834/IT+Sicherheit/Cybersecurity+Nachrichten/Erster+KI-entwickelter+Zero-Day-Angriff+auf+2FA-Systeme+identifiziert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519834/IT+Sicherheit/Cybersecurity+Nachrichten/Erster+KI-entwickelter+Zero-Day-Angriff+auf+2FA-Systeme+identifiziert/</guid>
<pubDate>Fri, 15 May 2026 15:13:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA]]></title> 
<description><![CDATA[Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a single password. The Tycoon 2FA phishing kit first gained attention as a Phishing-as-a-Service (PhaaS) platform. [&hellip;]
The post Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3519483/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Adopt+OAuth+Device+Code+Phishing+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519483/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Adopt+OAuth+Device+Code+Phishing+to+Bypass+MFA/</guid>
<pubDate>Fri, 15 May 2026 13:33:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA]]></title> 
<description><![CDATA[A new phishing campaign uncovered in late April 2026 shows how threat actors behind the Tycoon 2FA Phishing-as-a-Service (PhaaS) kit are evolving beyond traditional credential theft. This development comes just weeks after a global takedown effort led by Microsoft and&hellip;
Read more &rarr;
The post Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3519015/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Use+OAuth+Device+Code+Phishing+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519015/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Use+OAuth+Device+Code+Phishing+to+Bypass+MFA/</guid>
<pubDate>Fri, 15 May 2026 11:03:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA]]></title> 
<description><![CDATA[A new phishing campaign uncovered in late April 2026 shows how threat actors behind the Tycoon 2FA Phishing-as-a-Service (PhaaS) kit are evolving beyond traditional credential theft. This development comes just weeks after a global takedown effort led by Microsoft and Europol disrupted Tycoon 2FA infrastructure. Despite that operation, the actors have quickly adapted, reusing their [&hellip;]
The post Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3518984/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Use+OAuth+Device+Code+Phishing+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518984/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Operators+Use+OAuth+Device+Code+Phishing+to+Bypass+MFA/</guid>
<pubDate>Fri, 15 May 2026 10:37:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation]]></title> 
<description><![CDATA[Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.
The activity is said to be the work of cybercrime threat actors who appear to ]]></description>
<link>https://tsecurity.de/de/3507857/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Used+AI+to+Develop+First+Known+Zero-Day+2FA+Bypass+for+Mass+Exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507857/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Used+AI+to+Develop+First+Known+Zero-Day+2FA+Bypass+for+Mass+Exploitation/</guid>
<pubDate>Mon, 11 May 2026 17:45:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation]]></title> 
<description><![CDATA[Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the&hellip;
Read more &rarr;
The post Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3507849/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Used+AI+to+Develop+First+Known+Zero-Day+2FA+Bypass+for+Mass+Exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507849/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+Used+AI+to+Develop+First+Known+Zero-Day+2FA+Bypass+for+Mass+Exploitation/</guid>
<pubDate>Mon, 11 May 2026 19:03:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Nextcloud-2FA und Zugriffsschutz: So geht’s!]]></title> 
<description><![CDATA[Nextcloud eignet sich ideal, um sensible Dateien, Projektdaten und interne Dokumente zentral zu verwalten. Damit unbefugte Personen keinen Zugriff erhalten, sollten Sie den Login nicht nur mit einem Passwort sch&uuml;tzen. Die Nextcloud-2FA erg&auml;nzt den Anmeldeprozess um einen zweiten Faktor wie TOTP-Code, Sicherheitsschl&uuml;ssel oder Ger&auml;tebest&auml;tigung. In diesem Artikel erfahren Sie, welche 2FA-Methoden Nextcloud unterst&uuml;tzt und wie Sie den Zugriffsschutz sinnvoll h&auml;rten. ]]></description>
<link>https://tsecurity.de/de/3506306/IT+Server/Nextcloud-2FA+und+Zugriffsschutz%3A+So+geht%E2%80%99s%21/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506306/IT+Server/Nextcloud-2FA+und+Zugriffsschutz%3A+So+geht%E2%80%99s%21/</guid>
<pubDate>Mon, 11 May 2026 10:05:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[trunk/5dfa71bf27be025e16e06f28d4337f935782fab7]]></title> 
<description><![CDATA[Fix torch.compile crash when unsupported type passed to tensor method&hellip; ]]></description>
<link>https://tsecurity.de/de/3497622/IT+Downloads/trunk%2F5dfa71bf27be025e16e06f28d4337f935782fab7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497622/IT+Downloads/trunk%2F5dfa71bf27be025e16e06f28d4337f935782fab7/</guid>
<pubDate>Fri, 08 May 2026 02:04:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Saiga 2FA: Gefährliches Phishing-Kit kehrt mit neuer Tarntechnik zurück - IT-Daily.net]]></title> 
<description><![CDATA[Neues Phishing-Kit im Fokus der Sicherheitsexperten. Barracuda Research hat eine neue Serie von Angriffen identifiziert, die dem Phishing-Kit Saiga&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3496591/IT+Sicherheit/Cybersecurity+Nachrichten/Saiga+2FA%3A+Gef%C3%A4hrliches+Phishing-Kit+kehrt+mit+neuer+Tarntechnik+zur%C3%BCck+-+IT-Daily.net/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496591/IT+Sicherheit/Cybersecurity+Nachrichten/Saiga+2FA%3A+Gef%C3%A4hrliches+Phishing-Kit+kehrt+mit+neuer+Tarntechnik+zur%C3%BCck+-+IT-Daily.net/</guid>
<pubDate>Thu, 07 May 2026 16:18:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Pflicht-2FA, Tags und mehr: Raspberry Pi Connect legt kräftig nach]]></title> 
<description><![CDATA[Die Raspberry Pi Foundation hat ihrer Remote-Zugriffsl&ouml;sung Raspberry Pi Connect ein umfangreiches Update spendiert. Im Mittelpunkt steht dabei vor allem ein neues Sicherheitsfeature: Administratoren k&ouml;nnen k&uuml;nftig eine Zwei-Faktor-Authentifizierung (2FA) f&uuml;r s&auml;mtliche Mitglieder ihrer Organisation verpflichtend aktivieren. ]]></description>
<link>https://tsecurity.de/de/3495833/IT+Nachrichten/Pflicht-2FA%2C+Tags+und+mehr%3A+Raspberry+Pi+Connect+legt+kr%C3%A4ftig+nach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495833/IT+Nachrichten/Pflicht-2FA%2C+Tags+und+mehr%3A+Raspberry+Pi+Connect+legt+kr%C3%A4ftig+nach/</guid>
<pubDate>Thu, 07 May 2026 13:57:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Saiga 2FA: Gefährliches Phishing-Kit kehrt mit neuer Tarntechnik zurück]]></title> 
<description><![CDATA[
    Neue Analysen von Barracuda Research zeigen aktuelle Angriffswellen eines selten beobachteten Phishing-Kits mit dem Namen Saiga 2FA.

Tags: #Cyber Crime | #Cyberangriff | #PhaaS | #Phishing ]]></description>
<link>https://tsecurity.de/de/3495127/IT+Sicherheit/Cybersecurity+Nachrichten/Saiga+2FA%3A+Gef%C3%A4hrliches+Phishing-Kit+kehrt+mit+neuer+Tarntechnik+zur%C3%BCck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495127/IT+Sicherheit/Cybersecurity+Nachrichten/Saiga+2FA%3A+Gef%C3%A4hrliches+Phishing-Kit+kehrt+mit+neuer+Tarntechnik+zur%C3%BCck/</guid>
<pubDate>Thu, 07 May 2026 10:14:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Attacks Abuse Windows Phone Link to Steal Texts &amp; Bypass 2FA]]></title> 
<description><![CDATA[In hard-to-detect attacks, hackers are dropping the CloudZ RAT and a fresh plugin, Pheno, to hijack the Windows-based bridge between PCs and smartphones. ]]></description>
<link>https://tsecurity.de/de/3493087/IT+Sicherheit/Cybersecurity+Nachrichten/Attacks+Abuse+Windows+Phone+Link+to+Steal+Texts+%26amp%3Bamp%3B+Bypass+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493087/IT+Sicherheit/Cybersecurity+Nachrichten/Attacks+Abuse+Windows+Phone+Link+to+Steal+Texts+%26amp%3Bamp%3B+Bypass+2FA/</guid>
<pubDate>Wed, 06 May 2026 12:30:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking in One Panel]]></title> 
<description><![CDATA[A newly identified phishing kit called Bluekit is changing how cybercriminals carry out phishing attacks by packing multiple attack capabilities into a single, easy-to-use operator panel. Rather than relying on separate tools stitched together from different sources, Bluekit gives attackers&hellip;
Read more &rarr;
The post Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking in One Panel appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3486987/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Automates+Domains%2C+2FA+Lures%2C+and+Session+Hijacking+in+One+Panel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486987/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Automates+Domains%2C+2FA+Lures%2C+and+Session+Hijacking+in+One+Panel/</guid>
<pubDate>Mon, 04 May 2026 19:07:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking in One Panel]]></title> 
<description><![CDATA[A newly identified phishing kit called Bluekit is changing how cybercriminals carry out phishing attacks by packing multiple attack capabilities into a single, easy-to-use operator panel. Rather than relying on separate tools stitched together from different sources, Bluekit gives attackers one centralized platform to manage everything from fake website creation to session hijacking. For years, [&hellip;]
The post Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking in One Panel appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3486819/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Automates+Domains%2C+2FA+Lures%2C+and+Session+Hijacking+in+One+Panel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486819/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Automates+Domains%2C+2FA+Lures%2C+and+Session+Hijacking+in+One+Panel/</guid>
<pubDate>Mon, 04 May 2026 18:12:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Bluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session Hijacking]]></title> 
<description><![CDATA[A newly discovered phishing kit called &ldquo;Bluekit&rdquo; is reshaping how cybercriminals run phishing campaigns by combining multiple attack stages into a single, centralized platform. Instead, Bluekit integrates these capabilities into one operator panel, streamlining the entire attack lifecycle from setup&hellip;
Read more &rarr;
The post Bluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session Hijacking appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3486212/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Streamlines+Domains%2C+2FA+Lures%2C+and+Session+Hijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486212/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Streamlines+Domains%2C+2FA+Lures%2C+and+Session+Hijacking/</guid>
<pubDate>Mon, 04 May 2026 15:14:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Bluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session Hijacking]]></title> 
<description><![CDATA[A newly discovered phishing kit called &ldquo;Bluekit&rdquo; is reshaping how cybercriminals run phishing campaigns by combining multiple attack stages into a single, centralized platform. Instead, Bluekit integrates these capabilities into one operator panel, streamlining the entire attack lifecycle from setup to data exfiltration. This shift reflects a broader trend toward automation and ease of use [&hellip;]
The post Bluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session Hijacking appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3486174/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Streamlines+Domains%2C+2FA+Lures%2C+and+Session+Hijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486174/IT+Sicherheit/Cybersecurity+Nachrichten/Bluekit+Phishing+Kit+Streamlines+Domains%2C+2FA+Lures%2C+and+Session+Hijacking/</guid>
<pubDate>Mon, 04 May 2026 14:58:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Das unsichtbare Phishing-Kit: Saiga 2FA greift an]]></title> 
<description><![CDATA[Das unsichtbare Phishing-Kit: Saiga 2FA greift an

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Mo., 04.05.2026 - 11:25


            Sicherheitsforscher haben ein Phishing-Kit analysiert, das Metadaten mit sinnlosem Platzhaltertext f&uuml;llt, Entwicklertools erkennt und selbst Mehrfaktor-Authentifizierung aushebelt. Saiga 2FA ist selten &ndash; aber genau das macht es so gef&auml;hrlich.
      
    
          News
      
  
    Weiterlesen &uuml;ber Das unsichtbare Phishing-Kit: Saiga 2FA greift an   ]]></description>
<link>https://tsecurity.de/de/3485654/IT+Server/Das+unsichtbare+Phishing-Kit%3A+Saiga+2FA+greift+an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485654/IT+Server/Das+unsichtbare+Phishing-Kit%3A+Saiga+2FA+greift+an/</guid>
<pubDate>Mon, 04 May 2026 11:25:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands]]></title> 
<description><![CDATA[Bluekit centralizes and automates entire phishing campaigns, and is capable of stealing sessions, avoiding detection, and spoofing locations. ]]></description>
<link>https://tsecurity.de/de/3478121/IT+Nachrichten/Researchers+discover+new+all-in-one+%E2%80%98Bluekit%E2%80%99+phishing+kit+capable+of+bypassing+enterprise+2FA+protocols+and+emulating+40%2B+global+brands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478121/IT+Nachrichten/Researchers+discover+new+all-in-one+%E2%80%98Bluekit%E2%80%99+phishing+kit+capable+of+bypassing+enterprise+2FA+protocols+and+emulating+40%2B+global+brands/</guid>
<pubDate>Thu, 30 Apr 2026 17:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Beyond passwords: how the Tycoon 2FA phishing kit challenges MFA security]]></title> 
<description><![CDATA[Tycoon MFA phishing doesn&#039;t just bypass the logon, it exposes the real authentication battleground: what happens after initial access is granted ]]></description>
<link>https://tsecurity.de/de/3477966/IT+Sicherheit/Cybersecurity+Nachrichten/Beyond+passwords%3A+how+the+Tycoon+2FA+phishing+kit+challenges+MFA+security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477966/IT+Sicherheit/Cybersecurity+Nachrichten/Beyond+passwords%3A+how+the+Tycoon+2FA+phishing+kit+challenges+MFA+security/</guid>
<pubDate>Thu, 30 Apr 2026 02:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks]]></title> 
<description><![CDATA[Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform&rsquo;s disruption.
The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek. ]]></description>
<link>https://tsecurity.de/de/3444237/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Loses+Phishing+Kit+Crown+Amid+Surge+in+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3444237/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Loses+Phishing+Kit+Crown+Amid+Surge+in+Attacks/</guid>
<pubDate>Sat, 18 Apr 2026 12:30:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks]]></title> 
<description><![CDATA[Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform&rsquo;s disruption. The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the&hellip;
Read more &rarr;
The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3444236/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Loses+Phishing+Kit+Crown+Amid+Surge+in+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3444236/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Loses+Phishing+Kit+Crown+Amid+Surge+in+Attacks/</guid>
<pubDate>Sat, 18 Apr 2026 12:31:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing]]></title> 
<description><![CDATA[In embracing device code phishing, attackers trick victims into handing over account access by using a service&#039;s legitimate new-device login flow. ]]></description>
<link>https://tsecurity.de/de/3443216/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishers+Scatter%2C+Adopt+Device+Code+Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3443216/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishers+Scatter%2C+Adopt+Device+Code+Phishing/</guid>
<pubDate>Fri, 17 Apr 2026 21:05:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA is down, but not out – researchers warn the phishing as a service operation is still a huge threat to businesses]]></title> 
<description><![CDATA[Millions of Tycoon 2FA attacks are still hitting businesses, according to research from Barracuda ]]></description>
<link>https://tsecurity.de/de/3441786/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+is+down%2C+but+not+out+%E2%80%93+researchers+warn+the+phishing+as+a+service+operation+is+still+a+huge+threat+to+businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441786/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+is+down%2C+but+not+out+%E2%80%93+researchers+warn+the+phishing+as+a+service+operation+is+still+a+huge+threat+to+businesses/</guid>
<pubDate>Fri, 17 Apr 2026 13:05:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-32976 | Quest KACE SMA up to 14.1 2FA authentication bypass (EUVD-2025-19034 / Nessus ID 306731)]]></title> 
<description><![CDATA[A vulnerability was found in Quest KACE SMA up to 14.1. It has been rated as critical. This affects an unknown part of the component 2FA. The manipulation leads to authentication bypass using alternate channel.

This vulnerability is listed as CVE-2025-32976. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3440337/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-32976+%7C+Quest+KACE+SMA+up+to+14.1+2FA+authentication+bypass+%28EUVD-2025-19034+%2F+Nessus+ID+306731%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440337/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-32976+%7C+Quest+KACE+SMA+up+to+14.1+2FA+authentication+bypass+%28EUVD-2025-19034+%2F+Nessus+ID+306731%29/</guid>
<pubDate>Fri, 17 Apr 2026 00:44:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: Ente Auth encrypts, backs up, and syncs 2FA]]></title> 
<description><![CDATA[Two-factor authentication (2FA) is an essential layer of protection for online accounts, and Ente Auth makes it easier to manage securely across devices. Ente Auth is a free, open-source authenticator app designed to generate and store one-time passcodes for 2FA.&hellip;
Read more &rarr;
The post Product showcase: Ente Auth encrypts, backs up, and syncs 2FA appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3437503/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Ente+Auth+encrypts%2C+backs+up%2C+and+syncs+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437503/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Ente+Auth+encrypts%2C+backs+up%2C+and+syncs+2FA/</guid>
<pubDate>Thu, 16 Apr 2026 07:34:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: Ente Auth encrypts, backs up, and syncs 2FA]]></title> 
<description><![CDATA[Two-factor authentication (2FA) is an essential layer of protection for online accounts, and Ente Auth makes it easier to manage securely across devices. Ente Auth is a free, open-source authenticator app designed to generate and store one-time passcodes for 2FA. It supports setup through QR codes and manual entry, allowing users to add accounts and begin generating codes. Users can also import existing accounts from other authenticator apps, simplifying the transition without the need to &hellip; More &rarr;
The post Product showcase: Ente Auth encrypts, backs up, and syncs 2FA appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3437459/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Ente+Auth+encrypts%2C+backs+up%2C+and+syncs+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437459/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Ente+Auth+encrypts%2C+backs+up%2C+and+syncs+2FA/</guid>
<pubDate>Thu, 16 Apr 2026 07:00:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Breaking 2FA in WordPress: Account Takeover via CSRF in Google Authenticator]]></title> 
<description><![CDATA[In the WordPress ecosystem, security plugins are the first line of defense. However, when they fail, the impact can be critical.In this article, we analyze a Cross-Site Request Forgery (CSRF) vulnerability in the Google Authenticator plugin (ID, &#039;googleauthenticator_secret&#039;, $secret, true);     update_user_option($user-&gt;ID, &#039;googleauthenticator_enabled&#039;, &#039;enabled&#039;, true);   } }Root CauseThe developer completely omitted critical security controls:❌ check_admin_referer()❌ wp_verify_nonce()This enables classic CSRF attacks against an extremely sensitive functionality: 2FA configuration.Real-World Attack&nbsp;ScenarioThe attack is not just theoretical &mdash; it is highly exploitable and, when combined with social engineering, results in full account takeover:1. Attacker PreparationGenerates a valid secret (e.g., KRUGS4ZANFZSA43B)Adds it to their own Google Authenticator appSets up a phishing&nbsp;site2. Social EngineeringSends an email such as: Critical 2FA security update&nbsp;required3. Victim InteractionAdds the attacker&rsquo;s secret to their&nbsp;appGenerates a valid&nbsp;OTPEnters it into the malicious website4. CSRF ExecutionThe browser sends a legitimate POST request (without a&nbsp;nonce)WordPress accepts it as&nbsp;valid5. ResultThe 2FA secret is&nbsp;replacedThe admin is locked&nbsp;outThe attacker gains full&nbsp;accessAttack Demonstrationhttps://medium.com/media/6242ba7398727b3455d35cb8771c8f08/hrefImpactFull account&nbsp;takeoverPersistenceComplete 2FA&nbsp;bypassLoss of access for the legitimate administratorBreaking 2FA in WordPress: Account Takeover via CSRF in Google Authenticator was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story. ]]></description>
<link>https://tsecurity.de/de/3434219/IT+Sicherheit/Hacker/Breaking+2FA+in+WordPress%3A+Account+Takeover+via+CSRF+in+Google+Authenticator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434219/IT+Sicherheit/Hacker/Breaking+2FA+in+WordPress%3A+Account+Takeover+via+CSRF+in+Google+Authenticator/</guid>
<pubDate>Wed, 15 Apr 2026 07:57:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Someone (NOT ME) enabled 2FA on my account and now…]]></title> 
<description><![CDATA[I&rsquo;m locked out of my main account!!  I received an email this evening at about 5:16CT saying I&rsquo;d successfully enabled 2FA. I hadn&rsquo;t attempted to set up any such thing, so I knew then that somebody else had access to my account. Immediately, I changed the password for that account. I was able to successfully change it. When I tried to log back in with my new password, however, Reddit was requesting I enter the 2FA code or a backup code, both of which I had no access to because I am not the one who set up 2FA on my account. At that point, I decided I&rsquo;d submit a help request, and I was able to do that successfully.  All of this happened today within the past 30 minutes, so I figure it&rsquo;s typical that I don&rsquo;t have any response yet.  However, in the meantime, I decided to just look up my username from my burner account (the one I&rsquo;m currently typing this post from), and when I looked up my old username, it said my account had been bannd??????? As far as my conduct goes, that truly, no exaggeration could not be possible. I used Reddit on my (hacked, now maybe also bannd?) account this morning, engaging in very normal, pedestrian commenting. I had stopped using it for a while until I saw and read the &ldquo;2FA enabled email&rdquo;, upon which I then changed my password. So there was no rule breaking conduct on my part.  Does anyone have any idea about what more I can do here? I did submit a help request, but&hellip; I guess I&rsquo;m asking has anyone ever seen anything like this happening? Has anyone who&rsquo;s dealt with it have a good outcome in the end? I am so sad about this, I was nearing a 700 day streak on my account😭 I want access to all the conversations and comments and posts I&rsquo;ve saved, I didn&rsquo;t realize I was so attached to this account and now it seems to be just disappeared through no doing of my own.  The account is u/kweenofdelusion. Can anyone see anything related to my content? I cannot, but I&rsquo;m just asking if anyone else can.     submitted by    /u/micropommeolis   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3433672/IT+Sicherheit/Cybersecurity+Nachrichten/Someone+%28NOT+ME%29+enabled+2FA+on+my+account+and+now%E2%80%A6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433672/IT+Sicherheit/Cybersecurity+Nachrichten/Someone+%28NOT+ME%29+enabled+2FA+on+my+account+and+now%E2%80%A6/</guid>
<pubDate>Tue, 14 Apr 2026 01:51:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2023-6520 | WP 2FA Plugin up to 2.5.0 on WordPress cross-site request forgery]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in WP 2FA Plugin up to 2.5.0 on WordPress. This affects an unknown part. Performing a manipulation results in cross-site request forgery.

This vulnerability was named CVE-2023-6520. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3426134/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-6520+%7C+WP+2FA+Plugin+up+to+2.5.0+on+WordPress+cross-site+request+forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3426134/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-6520+%7C+WP+2FA+Plugin+up+to+2.5.0+on+WordPress+cross-site+request+forgery/</guid>
<pubDate>Sat, 11 Apr 2026 16:51:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2023-6506 | WP 2FA Plugin up to 2.5.0 on WordPress resource injection]]></title> 
<description><![CDATA[A vulnerability was found in WP 2FA Plugin up to 2.5.0 on WordPress. It has been rated as problematic. This impacts an unknown function. The manipulation leads to improper control of resource identifiers.

This vulnerability is traded as CVE-2023-6506. Access to the local network is required for this attack to succeed. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3426133/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-6506+%7C+WP+2FA+Plugin+up+to+2.5.0+on+WordPress+resource+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3426133/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-6506+%7C+WP+2FA+Plugin+up+to+2.5.0+on+WordPress+resource+injection/</guid>
<pubDate>Sat, 11 Apr 2026 16:51:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort]]></title> 
<description><![CDATA[Der neue Storm Infostealer umgeht 2FA, kapert Accounts per Session-Hijacking und entschl&uuml;sselt Daten serverseitig. Ein neuer Schadcode hebelt&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3414976/IT+Sicherheit/Cybersecurity+Nachrichten/Storm+Infostealer+umgeht+2FA%3A+Malware+%C3%BCbernimmt+Accounts+ohne+Passwort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414976/IT+Sicherheit/Cybersecurity+Nachrichten/Storm+Infostealer+umgeht+2FA%3A+Malware+%C3%BCbernimmt+Accounts+ohne+Passwort/</guid>
<pubDate>Tue, 07 Apr 2026 19:20:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Storm Infostealer umgeht 2FA: Malware übernimmt Accounts ohne Passwort]]></title> 
<description><![CDATA[Der neue Storm Infostealer umgeht 2FA, kapert Accounts per Session-Hijacking und entschl&uuml;sselt Daten serverseitig.
Der Artikel Storm Infostealer umgeht 2FA: Malware &uuml;bernimmt Accounts ohne Passwort erschien zuerst auf TARNKAPPE.INFO ]]></description>
<link>https://tsecurity.de/de/3414975/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Storm+Infostealer+umgeht+2FA%3A+Malware+%C3%BCbernimmt+Accounts+ohne+Passwort/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414975/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Storm+Infostealer+umgeht+2FA%3A+Malware+%C3%BCbernimmt+Accounts+ohne+Passwort/</guid>
<pubDate>Tue, 07 Apr 2026 19:18:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[New RBI Rule Makes 2FA Mandatory for All Digital Payments]]></title> 
<description><![CDATA[Two-factor authentication (2FA) will be required for all digital transactions under the new framework, drastically altering how customers pay with cards, mobile wallets, and UPI. India plans to change its financial landscape as the Reserve Bank of India (RBI) brings&hellip;
Read more &rarr;
The post New RBI Rule Makes 2FA Mandatory for All Digital Payments appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3411480/IT+Sicherheit/Cybersecurity+Nachrichten/New+RBI+Rule+Makes+2FA+Mandatory+for+All+Digital+Payments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411480/IT+Sicherheit/Cybersecurity+Nachrichten/New+RBI+Rule+Makes+2FA+Mandatory+for+All+Digital+Payments/</guid>
<pubDate>Mon, 06 Apr 2026 17:34:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app]]></title> 
<description><![CDATA[Proton Authenticator is a free and open-source two-factor authentication (2FA) app that generates time-based one-time passwords (TOTP) to help secure online accounts. It is available on Windows, macOS, Linux, iOS, and Android, allowing users to access their verification codes across&hellip;
Read more &rarr;
The post Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3410319/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Proton+Authenticator+is+an+end-to-end+encrypted%2C+open+source+2FA+app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410319/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Proton+Authenticator+is+an+end-to-end+encrypted%2C+open+source+2FA+app/</guid>
<pubDate>Mon, 06 Apr 2026 07:32:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app]]></title> 
<description><![CDATA[Proton Authenticator is a free and open-source two-factor authentication (2FA) app that generates time-based one-time passwords (TOTP) to help secure online accounts. It is available on Windows, macOS, Linux, iOS, and Android, allowing users to access their verification codes across devices. The app is designed to work without ads or tracking. A Proton account is optional and mainly used for encrypted sync between devices. How Proton Authenticator works Setup starts with installing the app from &hellip; More &rarr;
The post Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3410260/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Proton+Authenticator+is+an+end-to-end+encrypted%2C+open+source+2FA+app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410260/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+Proton+Authenticator+is+an+end-to-end+encrypted%2C+open+source+2FA+app/</guid>
<pubDate>Mon, 06 Apr 2026 07:00:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2024-46766 | Linux Kernel up to 6.10.9 netif_queue_set_napi out-of-bounds write (2285c2faef19/2a5dc090b92c / Nessus ID 210940)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.10.9. It has been rated as critical. This issue affects the function netif_queue_set_napi. This manipulation causes out-of-bounds write.

This vulnerability appears as CVE-2024-46766. The attacker needs to be present on the local network. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3409991/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-46766+%7C+Linux+Kernel+up+to+6.10.9+netif_queue_set_napi+out-of-bounds+write+%282285c2faef19%2F2a5dc090b92c+%2F+Nessus+ID+210940%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3409991/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-46766+%7C+Linux+Kernel+up+to+6.10.9+netif_queue_set_napi+out-of-bounds+write+%282285c2faef19%2F2a5dc090b92c+%2F+Nessus+ID+210940%29/</guid>
<pubDate>Mon, 06 Apr 2026 01:14:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-4924 | Devolutions Server up to 2026.1.11 2FA weak authentication (DEVO-2026-0010 / WID-SEC-2026-0958)]]></title> 
<description><![CDATA[A vulnerability was found in Devolutions Server up to 2026.1.11. It has been rated as critical. Affected is an unknown function of the component 2FA. The manipulation leads to weak authentication.

This vulnerability is listed as CVE-2026-4924. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3405126/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4924+%7C+Devolutions+Server+up+to+2026.1.11+2FA+weak+authentication+%28DEVO-2026-0010+%2F+WID-SEC-2026-0958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405126/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4924+%7C+Devolutions+Server+up+to+2026.1.11+2FA+weak+authentication+%28DEVO-2026-0010+%2F+WID-SEC-2026-0958%29/</guid>
<pubDate>Fri, 03 Apr 2026 11:42:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2024-32568 | Melapress WP 2FA Plugin up to 2.6.2 on WordPress cross site scripting]]></title> 
<description><![CDATA[A vulnerability has been found in Melapress WP 2FA Plugin up to 2.6.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.

This vulnerability is handled as CVE-2024-32568. The attack can be initiated remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3400954/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-32568+%7C+Melapress+WP+2FA+Plugin+up+to+2.6.2+on+WordPress+cross+site+scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400954/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-32568+%7C+Melapress+WP+2FA+Plugin+up+to+2.6.2+on+WordPress+cross+site+scripting/</guid>
<pubDate>Thu, 02 Apr 2026 00:16:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How is 2FA different from just having 2 passwords?]]></title> 
<description><![CDATA[I am talking about TOTP from authenticator apps. From my understanding, the TOTP is fully determined by the secret key. Then isn&rsquo;t it effectively the same level of security as simply having two passwords? Is the main advantage that these two are (ideally) stored in two different locations so it&rsquo;s harder to gain access to both?  Both my password manager and the authenticator app live on my phone, so getting access to my phone already exposes both. Also I guess entering the TOTP is safer because it does not expose your secret key, making it more resilient to key-loggers and phishing attacks. But then what is the need for the password itself, why not just have the TOTP to log in?    submitted by    /u/Paumas   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3391720/IT+Sicherheit/Cybersecurity+Nachrichten/How+is+2FA+different+from+just+having+2+passwords%3F/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3391720/IT+Sicherheit/Cybersecurity+Nachrichten/How+is+2FA+different+from+just+having+2+passwords%3F/</guid>
<pubDate>Sun, 29 Mar 2026 14:28:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations]]></title> 
<description><![CDATA[Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI&trade;. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying. ]]></description>
<link>https://tsecurity.de/de/3385249/IT+Sicherheit/Cybersecurity+Nachrichten/Europol%2C+Microsoft%2C+TrendAI%E2%84%A2+and+Collaborators+Halt+Tycoon+2FA+Operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385249/IT+Sicherheit/Cybersecurity+Nachrichten/Europol%2C+Microsoft%2C+TrendAI%E2%84%A2+and+Collaborators+Halt+Tycoon+2FA+Operations/</guid>
<pubDate>Wed, 04 Mar 2026 01:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Cloud-based Phishing Resumes After Tycoon2FA Disruption]]></title> 
<description><![CDATA[On March 4, 2026, Europol and global partners announced the technical disruption of Tycoon2FA, a major phishing-as-a-service platform. This service allowed cybercriminals to bypass multifactor authentication and compromise cloud email accounts. Authorities seized 330 domains that formed the core of the platform&rsquo;s infrastructure. In mid-2025, Tycoon2FA accounted for 62% of all phishing attempts blocked by [&hellip;]
The post Cloud-based Phishing Resumes After Tycoon2FA Disruption appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3379985/IT+Sicherheit/Cybersecurity+Nachrichten/Cloud-based+Phishing+Resumes+After+Tycoon2FA+Disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3379985/IT+Sicherheit/Cybersecurity+Nachrichten/Cloud-based+Phishing+Resumes+After+Tycoon2FA+Disruption/</guid>
<pubDate>Wed, 25 Mar 2026 13:13:32 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption]]></title> 
<description><![CDATA[Cybercriminals behind Tycoon2FA, a phishing-as-a-service (PhaaS) platform, have resumed targeting cloud accounts with near-full force despite a coordinated law enforcement takedown on March 4, 2026. Europol, working alongside authorities from six countries, seized 330 domains that formed the backbone of&hellip;
Read more &rarr;
The post Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3377957/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+After+Infrastructure+Disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377957/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+After+Infrastructure+Disruption/</guid>
<pubDate>Tue, 24 Mar 2026 20:34:29 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption]]></title> 
<description><![CDATA[Cybercriminals behind Tycoon2FA, a phishing-as-a-service (PhaaS) platform, have resumed targeting cloud accounts with near-full force despite a coordinated law enforcement takedown on March 4, 2026. Europol, working alongside authorities from six countries, seized 330 domains that formed the backbone of the platform&rsquo;s infrastructure in what became one of the more visible efforts to disrupt a [&hellip;]
The post Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3377694/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+After+Infrastructure+Disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377694/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+After+Infrastructure+Disruption/</guid>
<pubDate>Tue, 24 Mar 2026 18:22:57 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure]]></title> 
<description><![CDATA[Tycoon2FA operators have resumed large-scale cloud account phishing just days after law enforcement and industry partners disrupted the platform&rsquo;s core infrastructure, underscoring the resilience of phishing-as-a-service (PhaaS) ecosystems and the limits of infrastructure-only takedowns. Authorities in Latvia, Lithuania, Portugal, Poland, Spain, and the UK worked with private-sector partners to seize 330 domains used to power [&hellip;]
The post Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3376569/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+Following+Infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376569/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+Following+Infrastructure/</guid>
<pubDate>Tue, 24 Mar 2026 13:32:24 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure]]></title> 
<description><![CDATA[Tycoon2FA operators have resumed large-scale cloud account phishing just days after law enforcement and industry partners disrupted the platform&rsquo;s core infrastructure, underscoring the resilience of phishing-as-a-service (PhaaS) ecosystems and the limits of infrastructure-only takedowns. Authorities in Latvia, Lithuania, Portugal, Poland,&hellip;
Read more &rarr;
The post Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3376555/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+Following+Infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376555/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Operators+Resume+Cloud+Account+Phishing+Following+Infrastructure/</guid>
<pubDate>Tue, 24 Mar 2026 13:35:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Beyond KDE Connect for Android: What are you using for 2FA-Unlock, Media Control, and Notifications?]]></title> 
<description><![CDATA[Hey everyone, I&rsquo;ve been a long-time user of KDE Connect (and GSConnect) for the Android-Linux integration. While it&#039;s great, I&#039;m specifically looking for tools or workflows that excel in local security and seamless control rather than just file sharing. My main priorities are:  Local 2FA / Auto-Unlock: Using the phone as a trusted device to keep the PC unlocked or to handle authentication (like pam_kdeconnect or similar). Robust Media Control: High-quality integration with local players and browsers. Notification Sync: Reliable mirroring without the occasional &quot;delayed sync&quot; issues.  I&rsquo;m less interested in file transfers and more in making the phone a &quot;security key + remote control&quot; for the desktop.  Are you still using KDE Connect for this, or have you integrated things like Yubico Authenticator, Google&#039;s &#039;Nearby Unlock&#039; equivalents on Linux, or custom PAM modules? Any Wayland-specific tools that handle notification mirroring or media control better than the standard GSConnect/KDE Connect implementation?  Looking for any &quot;hidden gems&quot; or custom scripts you guys use to bridge the gap between Android and your Linux workstation.    submitted by    /u/Aruscha   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3375163/IT+Betriebssysteme/Linux+Tipps/Beyond+KDE+Connect+for+Android%3A+What+are+you+using+for+2FA-Unlock%2C+Media+Control%2C+and+Notifications%3F/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375163/IT+Betriebssysteme/Linux+Tipps/Beyond+KDE+Connect+for+Android%3A+What+are+you+using+for+2FA-Unlock%2C+Media+Control%2C+and+Notifications%3F/</guid>
<pubDate>Mon, 23 Mar 2026 19:36:20 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA phishing platform returns after recent police disruption]]></title> 
<description><![CDATA[The Tycoon2FA phishing-as-a-service (PhaaS) platform that Europol and partners disrupted on March 4 has already returned to previously observed activity levels. [...] ]]></description>
<link>https://tsecurity.de/de/3374928/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+phishing+platform+returns+after+recent+police+disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3374928/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+phishing+platform+returns+after+recent+police+disruption/</guid>
<pubDate>Mon, 23 Mar 2026 22:52:58 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Phishing Service Resumes Activity Post-Takedown]]></title> 
<description><![CDATA[Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA This article has been indexed from www.infosecurity-magazine.com Read the original article: Tycoon2FA Phishing Service Resumes Activity Post-Takedown
Read more &rarr;
The post Tycoon2FA Phishing Service Resumes Activity Post-Takedown appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3374317/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing+Service+Resumes+Activity+Post-Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3374317/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing+Service+Resumes+Activity+Post-Takedown/</guid>
<pubDate>Mon, 23 Mar 2026 17:36:27 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Phishing Service Resumes Activity Post-Takedown]]></title> 
<description><![CDATA[Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA ]]></description>
<link>https://tsecurity.de/de/3374248/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing+Service+Resumes+Activity+Post-Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3374248/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing+Service+Resumes+Activity+Post-Takedown/</guid>
<pubDate>Mon, 23 Mar 2026 17:05:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Still Active After Takedown]]></title> 
<description><![CDATA[Tycoon 2FA remains a dominant phishing-as-a-service platform that effectively bypasses multi-factor authentication to compromise thousands of organizations globally. This article has been indexed from CyberMaterial Read the original article: Tycoon 2FA Still Active After Takedown
Read more &rarr;
The post Tycoon 2FA Still Active After Takedown appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3373610/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Still+Active+After+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3373610/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Still+Active+After+Takedown/</guid>
<pubDate>Mon, 23 Mar 2026 14:05:07 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Fully Operational Despite Law Enforcement Takedown]]></title> 
<description><![CDATA[Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged.
The post Tycoon 2FA Fully Operational Despite Law Enforcement Takedown appeared first on SecurityWeek. ]]></description>
<link>https://tsecurity.de/de/3373113/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Fully+Operational+Despite+Law+Enforcement+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3373113/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Fully+Operational+Despite+Law+Enforcement+Takedown/</guid>
<pubDate>Mon, 23 Mar 2026 11:29:52 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Fully Operational Despite Law Enforcement Takedown]]></title> 
<description><![CDATA[Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged. The post Tycoon 2FA Fully Operational Despite Law Enforcement Takedown appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Tycoon&hellip;
Read more &rarr;
The post Tycoon 2FA Fully Operational Despite Law Enforcement Takedown appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3373108/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Fully+Operational+Despite+Law+Enforcement+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3373108/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Fully+Operational+Despite+Law+Enforcement+Takedown/</guid>
<pubDate>Mon, 23 Mar 2026 11:34:38 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zwei-Faktor-Authentifizierung (2FA): Was ist das? - Jörg Schieb]]></title> 
<description><![CDATA[Warum ist 2FA f&uuml;r eure Cybersicherheit wichtig? Zwei-Faktor&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3368686/IT+Sicherheit/Cybersecurity+Nachrichten/Zwei-Faktor-Authentifizierung+%282FA%29%3A+Was+ist+das%3F+-+J%C3%B6rg+Schieb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368686/IT+Sicherheit/Cybersecurity+Nachrichten/Zwei-Faktor-Authentifizierung+%282FA%29%3A+Was+ist+das%3F+-+J%C3%B6rg+Schieb/</guid>
<pubDate>Sat, 21 Mar 2026 07:41:57 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown]]></title> 
<description><![CDATA[ ]]></description>
<link>https://tsecurity.de/de/3367694/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing-as-a-Service+Platform+Persists+Following+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3367694/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA+Phishing-as-a-Service+Platform+Persists+Following+Takedown/</guid>
<pubDate>Fri, 20 Mar 2026 06:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets]]></title> 
<description><![CDATA[A serious operational security failure by Russian state-linked hacking group FancyBear has given security researchers an unusually clear view into an active espionage campaign targeting government and military organizations across Europe. On March 11, 2026, threat intelligence firm Hunt.io published&hellip;
Read more &rarr;
The post FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3359733/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Exposure+Reveals+Stolen+Credentials%2C+2FA+Secrets+and+NATO-Linked+Targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359733/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Exposure+Reveals+Stolen+Credentials%2C+2FA+Secrets+and+NATO-Linked+Targets/</guid>
<pubDate>Wed, 18 Mar 2026 16:34:38 +0100</pubDate>
</item>
<item> 
<title><![CDATA[FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets]]></title> 
<description><![CDATA[A serious operational security failure by Russian state-linked hacking group FancyBear has given security researchers an unusually clear view into an active espionage campaign targeting government and military organizations across Europe. On March 11, 2026, threat intelligence firm Hunt.io published findings on a campaign it tracks as Operation Roundish, based on an exposed open-directory first [&hellip;]
The post FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3359531/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Exposure+Reveals+Stolen+Credentials%2C+2FA+Secrets+and+NATO-Linked+Targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359531/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Exposure+Reveals+Stolen+Credentials%2C+2FA+Secrets+and+NATO-Linked+Targets/</guid>
<pubDate>Wed, 18 Mar 2026 15:43:18 +0100</pubDate>
</item>
<item> 
<title><![CDATA[FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets]]></title> 
<description><![CDATA[FancyBear&rsquo;s latest operational security failure has exposed a live Russian espionage server packed with stolen credentials, 2FA secrets, and detailed insight into the ongoing targeting of European government and military networks. The exposed infrastructure, tied to APT28/FancyBear and previously reported&hellip;
Read more &rarr;
The post FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3359360/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Leak+Exposes+Stolen+Credentials%2C+2FA+Secrets%2C+NATO+Targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359360/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Leak+Exposes+Stolen+Credentials%2C+2FA+Secrets%2C+NATO+Targets/</guid>
<pubDate>Wed, 18 Mar 2026 14:38:55 +0100</pubDate>
</item>
<item> 
<title><![CDATA[FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets]]></title> 
<description><![CDATA[FancyBear&rsquo;s latest operational security failure has exposed a live Russian espionage server packed with stolen credentials, 2FA secrets, and detailed insight into the ongoing targeting of European government and military networks. The exposed infrastructure, tied to APT28/FancyBear and previously reported by CERT‑UA and Hunt.io, reveals both the scale of the compromises and the carelessness of [&hellip;]
The post FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3359268/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Leak+Exposes+Stolen+Credentials%2C+2FA+Secrets%2C+NATO+Targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359268/IT+Sicherheit/Cybersecurity+Nachrichten/FancyBear+Server+Leak+Exposes+Stolen+Credentials%2C+2FA+Secrets%2C+NATO+Targets/</guid>
<pubDate>Wed, 18 Mar 2026 14:21:24 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Cybercab, Golden Jackal, Mamba 2FA, Microsoft, iPhone thieves, esims, Aaran Leyland.. - SWN #421]]></title> 
<description><![CDATA[Cybercab, Golden Jackal, Mamba 2FA, Multi Microsoft, iPhone thieves, esims, Aaran Leyland, and More, on this edition of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-421 ]]></description>
<link>https://tsecurity.de/de/3356463/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercab%2C+Golden+Jackal%2C+Mamba+2FA%2C+Microsoft%2C+iPhone+thieves%2C+esims%2C+Aaran+Leyland..+-+SWN+%23421/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356463/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercab%2C+Golden+Jackal%2C+Mamba+2FA%2C+Microsoft%2C+iPhone+thieves%2C+esims%2C+Aaran+Leyland..+-+SWN+%23421/</guid>
<pubDate>Fri, 11 Oct 2024 20:25:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Govt Unravelling, AI Hijinx, Bot Chaos, Recall, Oracle, Slopesquatting, Tycoon 2FA... - PSW #870]]></title> 
<description><![CDATA[Govt Unravelling, AI Hijinx, Bot Chaos, Recall, Oracle, Slopesquatting, Tycoon 2FA, College, who knows, a lot more... On Paul&#039;s Security Weekly. Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-870 ]]></description>
<link>https://tsecurity.de/de/3356295/IT+Sicherheit/Cybersecurity+Nachrichten/Govt+Unravelling%2C+AI+Hijinx%2C+Bot+Chaos%2C+Recall%2C+Oracle%2C+Slopesquatting%2C+Tycoon+2FA...+-+PSW+%23870/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356295/IT+Sicherheit/Cybersecurity+Nachrichten/Govt+Unravelling%2C+AI+Hijinx%2C+Bot+Chaos%2C+Recall%2C+Oracle%2C+Slopesquatting%2C+Tycoon+2FA...+-+PSW+%23870/</guid>
<pubDate>Thu, 17 Apr 2025 23:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Iran vs Everyone: 2FA-Bypass Phish, APT41 Drive, iOS 0days, Josh Marpet, and More - SWN #561]]></title> 
<description><![CDATA[Iran vs Everyone: 2FA-Bypass Phish, APT41 Drive, iOS 0days, Josh Marpet, and More on the Security Weekly News Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-561 ]]></description>
<link>https://tsecurity.de/de/3356018/IT+Sicherheit/Cybersecurity+Nachrichten/Iran+vs+Everyone%3A+2FA-Bypass+Phish%2C+APT41+Drive%2C+iOS+0days%2C+Josh+Marpet%2C+and+More+-+SWN+%23561/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356018/IT+Sicherheit/Cybersecurity+Nachrichten/Iran+vs+Everyone%3A+2FA-Bypass+Phish%2C+APT41+Drive%2C+iOS+0days%2C+Josh+Marpet%2C+and+More+-+SWN+%23561/</guid>
<pubDate>Fri, 06 Mar 2026 23:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-32133 | Bubka 2FAuth up to 6.0.x Image Parser image server-side request forgery (GHSA-8qp3-x2mp-j6f8)]]></title> 
<description><![CDATA[A vulnerability was found in Bubka 2FAuth up to 6.0.x. It has been rated as critical. Affected by this issue is some unknown functionality of the component Image Parser. Performing a manipulation of the argument image results in server-side request forgery.

This vulnerability is reported as CVE-2026-32133. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3350114/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-32133+%7C+Bubka+2FAuth+up+to+6.0.x+Image+Parser+image+server-side+request+forgery+%28GHSA-8qp3-x2mp-j6f8%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3350114/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-32133+%7C+Bubka+2FAuth+up+to+6.0.x+Image+Parser+image+server-side+request+forgery+%28GHSA-8qp3-x2mp-j6f8%29/</guid>
<pubDate>Sun, 15 Mar 2026 00:19:56 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform]]></title> 
<description><![CDATA[ ]]></description>
<link>https://tsecurity.de/de/3348397/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Goes+Boom+as+Europol%2C+Vendors+Bust+Phishing+Platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3348397/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Goes+Boom+as+Europol%2C+Vendors+Bust+Phishing+Platform/</guid>
<pubDate>Thu, 05 Mar 2026 15:19:20 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Law enforcement disrupts Tycoon 2FA phishing-as-a-service platform.]]></title> 
<description><![CDATA[FBI and Europol seize Leakbase cybercriminal forum. Cisco warns of fresh Catalyst SD-WAN exploits. ]]></description>
<link>https://tsecurity.de/de/3346691/IT+Sicherheit/Cybersecurity+Nachrichten/Law+enforcement+disrupts+Tycoon+2FA+phishing-as-a-service+platform./</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346691/IT+Sicherheit/Cybersecurity+Nachrichten/Law+enforcement+disrupts+Tycoon+2FA+phishing-as-a-service+platform./</guid>
<pubDate>Thu, 05 Mar 2026 18:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2FAS Pass: WLAN-Zugangsdaten lassen sich speichern und teilen]]></title> 
<description><![CDATA[Service-News f&uuml;r Nutzer der 2FAS-Pass-App: 2FAS Pass hat ein Update erhalten. Neuerdings lassen sich dort auch WLAN-Zugangsdaten sicher ablegen. Das Ganze dient nicht nur als Gedankenst&uuml;tze, sondern erleichtert auch die Weitergabe. Wer das Netzwerk mit anderen teilen m&ouml;chte, generiert einfach...Zum Beitrag: 2FAS Pass: WLAN-Zugangsdaten lassen sich speichern und teilen

 ]]></description>
<link>https://tsecurity.de/de/3339658/IT+Nachrichten/2FAS+Pass%3A+WLAN-Zugangsdaten+lassen+sich+speichern+und+teilen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3339658/IT+Nachrichten/2FAS+Pass%3A+WLAN-Zugangsdaten+lassen+sich+speichern+und+teilen/</guid>
<pubDate>Tue, 10 Mar 2026 20:30:07 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform]]></title> 
<description><![CDATA[Authorities disrupted the Tycoon 2FA phishing-as-a-service platform used to send millions of phishing emails to over 500,000 orgs worldwide. The joint effort, led by Microsoft, Europol, and industry partners, aimed to target the infrastructure of Tycoon 2FA phishing-as-a-service platform responsible&hellip;
Read more &rarr;
The post Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3337790/IT+Sicherheit/Cybersecurity+Nachrichten/Law+enforcement+disrupted+Tycoon+2FA+phishing-as-a-service+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3337790/IT+Sicherheit/Cybersecurity+Nachrichten/Law+enforcement+disrupted+Tycoon+2FA+phishing-as-a-service+platform/</guid>
<pubDate>Tue, 10 Mar 2026 10:07:55 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform]]></title> 
<description><![CDATA[Authorities disrupted the Tycoon 2FA phishing-as-a-service platform used to send millions of phishing emails to over 500,000 orgs worldwide. The joint effort, led by Microsoft, Europol, and industry partners, aimed to target the infrastructure of Tycoon 2FA phishing-as-a-service platform responsible for tens of millions of fraudulent emails reaching over 500,000 organizations each month worldwide. By [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3337705/IT+Sicherheit/Hacker/Law+enforcement+disrupted+Tycoon+2FA+phishing-as-a-service+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3337705/IT+Sicherheit/Hacker/Law+enforcement+disrupted+Tycoon+2FA+phishing-as-a-service+platform/</guid>
<pubDate>Tue, 10 Mar 2026 09:30:52 +0100</pubDate>
</item>
<item> 
<title><![CDATA[AiTM-Plattform Tycoon 2FA zerschlagen - CRN DE]]></title> 
<description><![CDATA[Eine internationale Allianz aus Herstellern wie Microsoft, IT-Security-Anbietern wie Proofpoint und Cloudfare sowie Beh&ouml;rden wie Europol und&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3336207/IT+Sicherheit/Cybersecurity+Nachrichten/AiTM-Plattform+Tycoon+2FA+zerschlagen+-+CRN+DE/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3336207/IT+Sicherheit/Cybersecurity+Nachrichten/AiTM-Plattform+Tycoon+2FA+zerschlagen+-+CRN+DE/</guid>
<pubDate>Mon, 09 Mar 2026 14:26:42 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Takedown von MFA-Bypass-Plattform Tycoon2FA | Borns IT- und Windows-BlogBorns IT]]></title> 
<description><![CDATA[Takedown von MFA-Bypass-Plattform Tycoon2FA. Ver&ouml;ffentlicht am 8. M&auml;rz 2026 von G&uuml;nter Born. Sicherheit (Pexels, allgemeine Nutzung)&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3333976/IT+Sicherheit/Cybersecurity+Nachrichten/Takedown+von+MFA-Bypass-Plattform+Tycoon2FA+%7C+Borns+IT-+und+Windows-BlogBorns+IT/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3333976/IT+Sicherheit/Cybersecurity+Nachrichten/Takedown+von+MFA-Bypass-Plattform+Tycoon2FA+%7C+Borns+IT-+und+Windows-BlogBorns+IT/</guid>
<pubDate>Sun, 08 Mar 2026 13:00:09 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Umgeht Passwörter und 2FA: Neue Hacker-Methode bedroht die Sicherheit von Microsoft-Konten]]></title> 
<description><![CDATA[Es gibt Angriffe, die eigentlich sofort auffallen m&uuml;ssten &ndash; und trotzdem funktionieren. Genau das zeigt eine neue Phishing-Technik,&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3333210/IT+Sicherheit/Hacker/Umgeht+Passw%C3%B6rter+und+2FA%3A+Neue+Hacker-Methode+bedroht+die+Sicherheit+von+Microsoft-Konten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3333210/IT+Sicherheit/Hacker/Umgeht+Passw%C3%B6rter+und+2FA%3A+Neue+Hacker-Methode+bedroht+die+Sicherheit+von+Microsoft-Konten/</guid>
<pubDate>Sun, 08 Mar 2026 00:09:16 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Takedown von MFA-Bypass-Plattform Tycoon2FA]]></title> 
<description><![CDATA[K&uuml;rzlich wurde die MFA-Bypass-Plattform Tycoon2FA beschlagnahmt und offline genommen. Die als f&uuml;hrend bezeichnete Phishing-as-a-Service-Plattform war darauf ausgelegt, Multi-Faktor-Authentifizierung zu umgehen und Konto&uuml;bernahmen im gro&szlig;en Stil zu erm&ouml;glichen. Trend Micro war an dieser Europol-Aktion beteiligt. Die Meldung Europol, Microsoft, TrendAI&trade; and &hellip; Weiterlesen &rarr;
Quelle ]]></description>
<link>https://tsecurity.de/de/3332885/IT+Nachrichten/Takedown+von+MFA-Bypass-Plattform+Tycoon2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3332885/IT+Nachrichten/Takedown+von+MFA-Bypass-Plattform+Tycoon2FA/</guid>
<pubDate>Sun, 08 Mar 2026 00:40:50 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Iran vs Everyone: 2FA-Bypass Phish, APT41 Drive, iOS 0days, Josh Marpet, and More - SWN #561]]></title> 
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:8 Iran vs Everyone: 2FA-Bypass Phish, APT41 Drive, iOS 0days, Josh Marpet, and More on the Security Weekly News

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://securityweekly.com/swn-561 ]]></description>
<link>https://tsecurity.de/de/3331284/IT+Sicherheit/Cybersecurity+Videos/Iran+vs+Everyone%3A+2FA-Bypass+Phish%2C+APT41+Drive%2C+iOS+0days%2C+Josh+Marpet%2C+and+More+-+SWN+%23561/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331284/IT+Sicherheit/Cybersecurity+Videos/Iran+vs+Everyone%3A+2FA-Bypass+Phish%2C+APT41+Drive%2C+iOS+0days%2C+Josh+Marpet%2C+and+More+-+SWN+%23561/</guid>
<pubDate>Fri, 06 Mar 2026 23:00:15 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Global coalition dismantles Tycoon 2FA phishing kit]]></title> 
<description><![CDATA[ ]]></description>
<link>https://tsecurity.de/de/3331251/IT+Sicherheit/Cybersecurity+Nachrichten/Global+coalition+dismantles+Tycoon+2FA+phishing+kit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3331251/IT+Sicherheit/Cybersecurity+Nachrichten/Global+coalition+dismantles+Tycoon+2FA+phishing+kit/</guid>
<pubDate>Wed, 04 Mar 2026 13:47:05 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA abgeschaltet: Schlag gegen weltweites AiTM-Phishing - IT-Daily.net]]></title> 
<description><![CDATA[... Hacking-Tools verantwortlich ist, werden erhebliche Auswirkungen auf das gesamte MFA-Credential-Phishing haben.&ldquo; AiTM-Phishing bleibt eine der&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3330607/IT+Sicherheit/Hacker/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing+-+IT-Daily.net/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3330607/IT+Sicherheit/Hacker/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing+-+IT-Daily.net/</guid>
<pubDate>Fri, 06 Mar 2026 16:00:57 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA abgeschaltet: Schlag gegen weltweites AiTM-Phishing - IT-Daily.net]]></title> 
<description><![CDATA[... das Handwerk legt. Tycoon 2FA abgeschaltet: Schlag gegen weltweites AiTM-Phishing. 6. M&auml;rz, 2026; 09:57. Hacker. Facebook X LinkedIn&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3330482/IT+Sicherheit/Hacker/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing+-+IT-Daily.net/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3330482/IT+Sicherheit/Hacker/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing+-+IT-Daily.net/</guid>
<pubDate>Fri, 06 Mar 2026 10:09:11 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA abgeschaltet: Schlag gegen weltweites AiTM-Phishing]]></title> 
<description><![CDATA[
    Eine internationale Kooperation aus Sicherheitsfirmen und Beh&ouml;rden hat die Infrastruktur von Tycoon 2FA, einer der meistgenutzten Phishing-as-a-Service-Plattformen, erfolgreich zerst&ouml;rt. 

Tags: #Cyberkriminelle | #Phishing | #Zerschlagung ]]></description>
<link>https://tsecurity.de/de/3329697/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3329697/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+abgeschaltet%3A+Schlag+gegen+weltweites+AiTM-Phishing/</guid>
<pubDate>Fri, 06 Mar 2026 09:57:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform]]></title> 
<description><![CDATA[The phishing-as-a-service platform was popular among cyber threat actors because of its ability to bypass multifactor authentication defenses. ]]></description>
<link>https://tsecurity.de/de/3329014/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Goes+Boom+as+Europol%2C+Vendors+Bust+Phishing+Platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3329014/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Goes+Boom+as+Europol%2C+Vendors+Bust+Phishing+Platform/</guid>
<pubDate>Thu, 05 Mar 2026 22:23:26 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA: Behörden legen große Phishing-Plattform lahm]]></title> 
<description><![CDATA[Es gibt mal wieder Neuigkeiten von der Front gegen Cyberkriminalit&auml;t, dieses Mal trifft es eine ziemlich gro&szlig;e Nummer. Eine international koordinierte Aktion hat die Phishing-as-a-Service-Plattform &bdquo;Tycoon 2FA&ldquo; vom Netz genommen. Das Ganze lief unter der Federf&uuml;hrung von Europol und involvierte...Zum Beitrag: Tycoon 2FA: Beh&ouml;rden legen gro&szlig;e Phishing-Plattform lahm

 ]]></description>
<link>https://tsecurity.de/de/3328675/IT+Nachrichten/Tycoon+2FA%3A+Beh%C3%B6rden+legen+gro%C3%9Fe+Phishing-Plattform+lahm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328675/IT+Nachrichten/Tycoon+2FA%3A+Beh%C3%B6rden+legen+gro%C3%9Fe+Phishing-Plattform+lahm/</guid>
<pubDate>Thu, 05 Mar 2026 18:30:24 +0100</pubDate>
</item>
<item> 
<title><![CDATA[LeakBase und Tycoon 2FA abgeschaltet: Doppelschlag gegen Cybercrime-Lieferkette]]></title> 
<description><![CDATA[LeakBase &amp; Tycoon 2FA abgeschaltet: Zwei internationale Aktionen treffen zentrale Dienste der Cybercrime-Infrastruktur. Innerhalb weniger Tage&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3328502/IT+Sicherheit/Cybersecurity+Nachrichten/LeakBase+und+Tycoon+2FA+abgeschaltet%3A+Doppelschlag+gegen+Cybercrime-Lieferkette/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328502/IT+Sicherheit/Cybersecurity+Nachrichten/LeakBase+und+Tycoon+2FA+abgeschaltet%3A+Doppelschlag+gegen+Cybercrime-Lieferkette/</guid>
<pubDate>Thu, 05 Mar 2026 17:50:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft, Europol disrupt global phishing platform Tycoon 2FA]]></title> 
<description><![CDATA[The service helped cybercriminals bypass multifactor authentication and led to business email compromise and ransomware. This article has been indexed from Cybersecurity Dive &ndash; Latest News Read the original article: Microsoft, Europol disrupt global phishing platform Tycoon 2FA
Read more &rarr;
The post Microsoft, Europol disrupt global phishing platform Tycoon 2FA appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3328479/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft%2C+Europol+disrupt+global+phishing+platform+Tycoon+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328479/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft%2C+Europol+disrupt+global+phishing+platform+Tycoon+2FA/</guid>
<pubDate>Thu, 05 Mar 2026 17:34:10 +0100</pubDate>
</item>
<item> 
<title><![CDATA[LeakBase und Tycoon 2FA abgeschaltet: Doppelschlag gegen Cybercrime-Lieferkette]]></title> 
<description><![CDATA[LeakBase &amp; Tycoon 2FA abgeschaltet: Zwei internationale Aktionen treffen zentrale Dienste der Cybercrime-Infrastruktur.
Der Artikel LeakBase und Tycoon 2FA abgeschaltet: Doppelschlag gegen Cybercrime-Lieferkette erschien zuerst auf TARNKAPPE.INFO ]]></description>
<link>https://tsecurity.de/de/3328473/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/LeakBase+und+Tycoon+2FA+abgeschaltet%3A+Doppelschlag+gegen+Cybercrime-Lieferkette/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328473/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/LeakBase+und+Tycoon+2FA+abgeschaltet%3A+Doppelschlag+gegen+Cybercrime-Lieferkette/</guid>
<pubDate>Thu, 05 Mar 2026 17:38:45 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft, Europol disrupt global phishing platform Tycoon 2FA]]></title> 
<description><![CDATA[The service helped cybercriminals bypass multifactor authentication and led to business email compromise and ransomware. ]]></description>
<link>https://tsecurity.de/de/3328390/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft%2C+Europol+disrupt+global+phishing+platform+Tycoon+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328390/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft%2C+Europol+disrupt+global+phishing+platform+Tycoon+2FA/</guid>
<pubDate>Thu, 05 Mar 2026 16:39:42 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Europol Busts Tycoon 2FA Phishing Service]]></title> 
<description><![CDATA[Law enforcement and security firms successfully dismantled Tycoon 2FA, a massive phishing-as-a-service platform that enabled criminals to bypass multi-factor authentication and harvest credentials. This article has been indexed from CyberMaterial Read the original article: Europol Busts Tycoon 2FA Phishing Service
Read more &rarr;
The post Europol Busts Tycoon 2FA Phishing Service appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3328095/IT+Sicherheit/Cybersecurity+Nachrichten/Europol+Busts+Tycoon+2FA+Phishing+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328095/IT+Sicherheit/Cybersecurity+Nachrichten/Europol+Busts+Tycoon+2FA+Phishing+Service/</guid>
<pubDate>Thu, 05 Mar 2026 15:09:22 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA]]></title> 
<description><![CDATA[Europol and partners dismantle Tycoon 2FA phishing service used to bypass MFA, disrupting a global phishing-as-a-service operation targeting organisations. This article has been indexed from Hackread &ndash; Cybersecurity News, Data Breaches, AI and More Read the original article: Authorities Shut&hellip;
Read more &rarr;
The post Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3327916/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+Shut+Down+Tycoon+2FA+Phishing+Platform+Used+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327916/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+Shut+Down+Tycoon+2FA+Phishing+Platform+Used+to+Bypass+MFA/</guid>
<pubDate>Thu, 05 Mar 2026 14:09:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA]]></title> 
<description><![CDATA[Europol and partners dismantle Tycoon 2FA phishing service used to bypass MFA, disrupting a global phishing-as-a-service operation targeting organisations. ]]></description>
<link>https://tsecurity.de/de/3327892/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+Shut+Down+Tycoon+2FA+Phishing+Platform+Used+to+Bypass+MFA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327892/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+Shut+Down+Tycoon+2FA+Phishing+Platform+Used+to+Bypass+MFA/</guid>
<pubDate>Thu, 05 Mar 2026 13:53:20 +0100</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-27801 | dani-garcia vaultwarden up to 1.34.x 2FA excessive authentication (GHSA-v6pg-v89r-w8wr / WID-SEC-2026-0594)]]></title> 
<description><![CDATA[A vulnerability was found in dani-garcia vaultwarden up to 1.34.x. It has been classified as problematic. This vulnerability affects unknown code of the component 2FA. The manipulation leads to improper restriction of excessive authentication attempts.

This vulnerability is uniquely identified as CVE-2026-27801. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3327550/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-27801+%7C+dani-garcia+vaultwarden+up+to+1.34.x+2FA+excessive+authentication+%28GHSA-v6pg-v89r-w8wr+%2F+WID-SEC-2026-0594%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327550/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-27801+%7C+dani-garcia+vaultwarden+up+to+1.34.x+2FA+excessive+authentication+%28GHSA-v6pg-v89r-w8wr+%2F+WID-SEC-2026-0594%29/</guid>
<pubDate>Thu, 05 Mar 2026 11:38:40 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Authorities pull plug on Tycoon 2FA phishing-as-a-service platform]]></title> 
<description><![CDATA[Tycoon 2FA, a phishing-as-a-service platform that allowed cybercriminals to bypass MFA and break into online accounts, has been disrupted by law enforcement agencies and cybersecurity partners. Takedown of the Tycoon 2FA phishing-as-a-service platform (Source: Europol) Active since August 2023, Tycoon&hellip;
Read more &rarr;
The post Authorities pull plug on Tycoon 2FA phishing-as-a-service platform appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3327282/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+pull+plug+on+Tycoon+2FA+phishing-as-a-service+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327282/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+pull+plug+on+Tycoon+2FA+phishing-as-a-service+platform/</guid>
<pubDate>Thu, 05 Mar 2026 10:07:20 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Authorities pull plug on Tycoon 2FA phishing-as-a-service platform]]></title> 
<description><![CDATA[Tycoon 2FA, a phishing-as-a-service platform that allowed cybercriminals to bypass MFA and break into online accounts, has been disrupted by law enforcement agencies and cybersecurity partners. Takedown of the Tycoon 2FA phishing-as-a-service platform (Source: Europol) Active since August 2023, Tycoon 2FA was among the largest phishing operations worldwide. At its peak, the platform accounted for about 62% of phishing attempts blocked by Microsoft, according to investigators. The service operated on a subscription model and gave &hellip; More &rarr;
The post Authorities pull plug on Tycoon 2FA phishing-as-a-service platform appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3327217/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+pull+plug+on+Tycoon+2FA+phishing-as-a-service+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327217/IT+Sicherheit/Cybersecurity+Nachrichten/Authorities+pull+plug+on+Tycoon+2FA+phishing-as-a-service+platform/</guid>
<pubDate>Thu, 05 Mar 2026 09:37:28 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Possible iPhone-hacking toolkit used by spies, Hacker mass-mails HungerRush extortion emails, Tycoon 2FA phishing platform dismantled]]></title> 
<description><![CDATA[Possible iPhone-hacking toolkit used by spies Hacker mass-mails HungerRush extortion emails Tycoon 2FA phishing platform dismantled Get the show notes here: https://cisoseries.com/cybersecurity-news-iphone-hacking-toolkit-used-by-spies-hungerrush-extortion-emails-tycoon-phishing-platform-dismantled/ Huge thanks to our sponsor, Adaptive Security This episode is brought to you by Adaptive Security, the first&hellip;
Read more &rarr;
The post Possible iPhone-hacking toolkit used by spies, Hacker mass-mails HungerRush extortion emails, Tycoon 2FA phishing platform dismantled appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3327188/IT+Sicherheit/Cybersecurity+Nachrichten/Possible+iPhone-hacking+toolkit+used+by+spies%2C+Hacker+mass-mails+HungerRush+extortion+emails%2C+Tycoon+2FA+phishing+platform+dismantled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327188/IT+Sicherheit/Cybersecurity+Nachrichten/Possible+iPhone-hacking+toolkit+used+by+spies%2C+Hacker+mass-mails+HungerRush+extortion+emails%2C+Tycoon+2FA+phishing+platform+dismantled/</guid>
<pubDate>Thu, 05 Mar 2026 09:32:13 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks]]></title> 
<description><![CDATA[Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that allowed cybercriminals to stage adversary-in-the-middle (AitM) credential harvesting attacks at scale, was dismantled by a coalition of law enforcement agencies and security companies.
The subscription-based phishing kit, which first emerged in August 2023, was described by Europol as one of the largest phishing ]]></description>
<link>https://tsecurity.de/de/3327071/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-Led+Operation+Takes+Down+Tycoon+2FA+Phishing-as-a-Service+Linked+to+64%2C000+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327071/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-Led+Operation+Takes+Down+Tycoon+2FA+Phishing-as-a-Service+Linked+to+64%2C000+Attacks/</guid>
<pubDate>Thu, 05 Mar 2026 07:51:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks]]></title> 
<description><![CDATA[Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that allowed cybercriminals to stage adversary-in-the-middle (AitM) credential harvesting attacks at scale, was dismantled by a coalition of law enforcement agencies and security companies. The subscription-based phishing kit, which first emerged&hellip;
Read more &rarr;
The post Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3327068/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-Led+Operation+Takes+Down+Tycoon+2FA+Phishing-as-a-Service+Linked+to+64%2C000+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327068/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-Led+Operation+Takes+Down+Tycoon+2FA+Phishing-as-a-Service+Linked+to+64%2C000+Attacks/</guid>
<pubDate>Thu, 05 Mar 2026 08:32:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft and Europol Take Down Tycoon 2FA Phishing Kit Used in Global Cyber Attacks]]></title> 
<description><![CDATA[Microsoft, Europol, and a coalition of industry partners have dismantled the Tycoon 2FA Phishing-as-a-Service (PhaaS) platform, a major adversary-in-the-middle (AiTM) operation that bypassed multi-factor authentication (MFA) for over 96,000 victims worldwide. Active since August 2023, this cybercrime service enables low-skilled attackers to steal credentials and session cookies in real time, targeting Microsoft 365 and Google [&hellip;]
The post Microsoft and Europol Take Down Tycoon 2FA Phishing Kit Used in Global Cyber Attacks appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3327013/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+and+Europol+Take+Down+Tycoon+2FA+Phishing+Kit+Used+in+Global+Cyber+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327013/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+and+Europol+Take+Down+Tycoon+2FA+Phishing+Kit+Used+in+Global+Cyber+Attacks/</guid>
<pubDate>Thu, 05 Mar 2026 07:59:10 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishing Operation Dismantled in Joint Raid by Microsoft and Europol]]></title> 
<description><![CDATA[Microsoft, Europol, and industry partners have successfully dismantled the Tycoon 2FA Phishing-as-a-Service (PhaaS) platform. Operating since August 2023, this immense adversary-in-the-middle (AiTM) operation allowed cybercriminals to bypass multi-factor authentication (MFA) and infiltrate over 96,000 distinct victims globally. This coordinated disruption&hellip;
Read more &rarr;
The post Tycoon 2FA Phishing Operation Dismantled in Joint Raid by Microsoft and Europol appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3326856/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Operation+Dismantled+in+Joint+Raid+by+Microsoft+and+Europol/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326856/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Operation+Dismantled+in+Joint+Raid+by+Microsoft+and+Europol/</guid>
<pubDate>Thu, 05 Mar 2026 06:16:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon2FA: Europol zerschlägt Phishing-as-a-Service-Plattform - Tagesspiegel Background]]></title> 
<description><![CDATA[Lesen Sie die neuesten Informationen zum Thema &quot;Europol zerschl&auml;gt Phishing-as-a-Service-Plattform&quot; aus unserem Tagesspiegel Briefing&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3326817/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA%3A+Europol+zerschl%C3%A4gt+Phishing-as-a-Service-Plattform+-+Tagesspiegel+Background/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326817/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon2FA%3A+Europol+zerschl%C3%A4gt+Phishing-as-a-Service-Plattform+-+Tagesspiegel+Background/</guid>
<pubDate>Thu, 05 Mar 2026 05:03:58 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Phishing-Plattform Tycoon 2FA zerschlagen: Europol koordiniert internationalen Behördeneinsatz]]></title> 
<description><![CDATA[All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). ... IT-Sicherheit &middot; Featured image for &ldquo;CrowdStrike Global Threat Report&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3326537/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Plattform+Tycoon+2FA+zerschlagen%3A+Europol+koordiniert+internationalen+Beh%C3%B6rdeneinsatz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326537/IT+Sicherheit/Cybersecurity+Nachrichten/Phishing-Plattform+Tycoon+2FA+zerschlagen%3A+Europol+koordiniert+internationalen+Beh%C3%B6rdeneinsatz/</guid>
<pubDate>Wed, 04 Mar 2026 18:28:57 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Einfallstore verteidigen: So gelang es, den Phishing-Dienst "Tycoon 2FA" abzuschalten]]></title> 
<description><![CDATA[Microsoft Security &middot; Azure &middot; Dynamics 365 &middot; Microsoft 365 &middot; Microsoft 365 Copilot &middot; Microsoft Teams &middot; Kleine Unternehmen. Entwicklung &amp; IT. Microsoft-&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3326461/IT+Sicherheit/Cybersecurity+Nachrichten/Einfallstore+verteidigen%3A+So+gelang+es%2C+den+Phishing-Dienst+%22Tycoon+2FA%22+abzuschalten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326461/IT+Sicherheit/Cybersecurity+Nachrichten/Einfallstore+verteidigen%3A+So+gelang+es%2C+den+Phishing-Dienst+%22Tycoon+2FA%22+abzuschalten/</guid>
<pubDate>Wed, 04 Mar 2026 18:11:03 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Cybercrime-Infrastruktur: Doppelschlag gegen LeakBase und Tycoon 2FA - Ad-hoc-news.de]]></title> 
<description><![CDATA[Die Aktion unterbricht die Lieferkette f&uuml;r gestohlene Daten und Phishing-Tools. Cybercrime-Infrastruktur: Doppelschlag&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3326329/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercrime-Infrastruktur%3A+Doppelschlag+gegen+LeakBase+und+Tycoon+2FA+-+Ad-hoc-news.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326329/IT+Sicherheit/Cybersecurity+Nachrichten/Cybercrime-Infrastruktur%3A+Doppelschlag+gegen+LeakBase+und+Tycoon+2FA+-+Ad-hoc-news.de/</guid>
<pubDate>Wed, 04 Mar 2026 21:14:44 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishing Platform Dismantled in Global Takedown]]></title> 
<description><![CDATA[The phishing-as-a-service platform was used to send fraudulent emails to over 500,000 organizations every month. The post Tycoon 2FA Phishing Platform Dismantled in Global Takedown appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:&hellip;
Read more &rarr;
The post Tycoon 2FA Phishing Platform Dismantled in Global Takedown appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3326219/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Platform+Dismantled+in+Global+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326219/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Platform+Dismantled+in+Global+Takedown/</guid>
<pubDate>Wed, 04 Mar 2026 20:07:33 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations]]></title> 
<description><![CDATA[Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI&trade;. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying. This article has been indexed from Trend Micro Research, News and Perspectives Read the original&hellip;
Read more &rarr;
The post Europol, Microsoft, TrendAI&trade; and Collaborators Halt Tycoon 2FA Operations appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3326218/IT+Sicherheit/Cybersecurity+Nachrichten/Europol%2C+Microsoft%2C+TrendAI%E2%84%A2+and+Collaborators+Halt+Tycoon+2FA+Operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326218/IT+Sicherheit/Cybersecurity+Nachrichten/Europol%2C+Microsoft%2C+TrendAI%E2%84%A2+and+Collaborators+Halt+Tycoon+2FA+Operations/</guid>
<pubDate>Wed, 04 Mar 2026 20:07:49 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishing Platform Dismantled in Global Takedown]]></title> 
<description><![CDATA[The phishing-as-a-service platform was used to send fraudulent emails to over 500,000 organizations every month.
The post Tycoon 2FA Phishing Platform Dismantled in Global Takedown appeared first on SecurityWeek. ]]></description>
<link>https://tsecurity.de/de/3326166/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Platform+Dismantled+in+Global+Takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326166/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Platform+Dismantled+in+Global+Takedown/</guid>
<pubDate>Wed, 04 Mar 2026 19:37:26 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners]]></title> 
<description><![CDATA[Microsoft, Europol, and partners have dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform, seizing 330 domains used for credential theft and MFA bypass. This coordinated action disrupts a service active since 2023 that powered tens of millions of phishing emails monthly.&hellip;
Read more &rarr;
The post Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3326145/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Kit+Disrupted+by+Microsoft%2C+Europol+and+Partners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326145/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Kit+Disrupted+by+Microsoft%2C+Europol+and+Partners/</guid>
<pubDate>Wed, 04 Mar 2026 19:34:16 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners]]></title> 
<description><![CDATA[Microsoft, Europol, and partners have dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform, seizing 330 domains used for credential theft and MFA bypass. This coordinated action disrupts a service active since 2023 that powered tens of millions of phishing emails monthly. Tycoon 2FA enabled cybercriminals to bypass multifactor authentication (MFA) via adversary-in-the-middle (AiTM) techniques, capturing credentials, [&hellip;]
The post Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3326078/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Kit+Disrupted+by+Microsoft%2C+Europol+and+Partners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326078/IT+Sicherheit/Cybersecurity+Nachrichten/Tycoon+2FA+Phishing+Kit+Disrupted+by+Microsoft%2C+Europol+and+Partners/</guid>
<pubDate>Wed, 04 Mar 2026 18:33:28 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale]]></title> 
<description><![CDATA[Tycoon2FA has become a leading phishing-as-a-service (PhaaS) platforms, enabling campaigns that reach over 500,000 organizations monthly, prompting Microsoft&rsquo;s Digital Crimes Unit (DCU) to work with Europol and industry partners to facilitate a disruption of Tycoon2FA&rsquo;s infrastructure and operations.
The post Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale appeared first on Microsoft Security Blog. ]]></description>
<link>https://tsecurity.de/de/3326007/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+Tycoon2FA%3A+How+a+leading+AiTM+phishing+kit+operated+at+scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326007/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+Tycoon2FA%3A+How+a+leading+AiTM+phishing+kit+operated+at+scale/</guid>
<pubDate>Wed, 04 Mar 2026 17:04:24 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Einfallstore verteidigen: So gelang es, den Phishing-Dienst "Tycoon 2FA" abzuschalten]]></title> 
<description><![CDATA[Die internationale Operation umfasste gerichtliche Ma&szlig;nahmen in den USA sowie die Sicherstellung von Server ... Windows 11-Apps. Microsoft Store. ]]></description>
<link>https://tsecurity.de/de/3325963/IT+Server/Windows+Server/Einfallstore+verteidigen%3A+So+gelang+es%2C+den+Phishing-Dienst+%22Tycoon+2FA%22+abzuschalten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325963/IT+Server/Windows+Server/Einfallstore+verteidigen%3A+So+gelang+es%2C+den+Phishing-Dienst+%22Tycoon+2FA%22+abzuschalten/</guid>
<pubDate>Wed, 04 Mar 2026 17:40:27 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Europol-coordinated action disrupts Tycoon2FA phishing platform]]></title> 
<description><![CDATA[An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month. [...] ]]></description>
<link>https://tsecurity.de/de/3325941/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-coordinated+action+disrupts+Tycoon2FA+phishing+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325941/IT+Sicherheit/Cybersecurity+Nachrichten/Europol-coordinated+action+disrupts+Tycoon2FA+phishing+platform/</guid>
<pubDate>Wed, 04 Mar 2026 18:01:26 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale]]></title> 
<description><![CDATA[Tycoon2FA has become a leading phishing-as-a-service (PhaaS) platforms, enabling campaigns that reach over 500,000 organizations monthly, prompting Microsoft&rsquo;s Digital Crimes Unit (DCU) to work with Europol and industry partners to facilitate a disruption of Tycoon2FA&rsquo;s infrastructure and operations. The post&hellip;
Read more &rarr;
The post Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3325938/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+Tycoon2FA%3A+How+a+leading+AiTM+phishing+kit+operated+at+scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325938/IT+Sicherheit/Cybersecurity+Nachrichten/Inside+Tycoon2FA%3A+How+a+leading+AiTM+phishing+kit+operated+at+scale/</guid>
<pubDate>Wed, 04 Mar 2026 18:05:03 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Global Takedown Neutralizes Tycoon2FA Phishing Service]]></title> 
<description><![CDATA[Law enforcers and industry partners have taken down notorious phishing-as-a-service platform Tycoon2FA This article has been indexed from www.infosecurity-magazine.com Read the original article: Global Takedown Neutralizes Tycoon2FA Phishing Service
Read more &rarr;
The post Global Takedown Neutralizes Tycoon2FA Phishing Service appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3325822/IT+Sicherheit/Cybersecurity+Nachrichten/Global+Takedown+Neutralizes+Tycoon2FA+Phishing+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325822/IT+Sicherheit/Cybersecurity+Nachrichten/Global+Takedown+Neutralizes+Tycoon2FA+Phishing+Service/</guid>
<pubDate>Wed, 04 Mar 2026 17:11:33 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Global Takedown Neutralizes Tycoon2FA Phishing Service]]></title> 
<description><![CDATA[Law enforcers and industry partners have taken down notorious phishing-as-a-service platform Tycoon2FA ]]></description>
<link>https://tsecurity.de/de/3325776/IT+Sicherheit/Cybersecurity+Nachrichten/Global+Takedown+Neutralizes+Tycoon2FA+Phishing+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325776/IT+Sicherheit/Cybersecurity+Nachrichten/Global+Takedown+Neutralizes+Tycoon2FA+Phishing+Service/</guid>
<pubDate>Wed, 04 Mar 2026 17:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Defending the gates: How a global coalition disrupted Tycoon 2FA, a major driver of initial access and large-scale online impersonation]]></title> 
<description><![CDATA[One email was all it took. An employee clicked what looked like a routine sign‑in request. Behind the scenes, attackers&nbsp;swiped&nbsp;credentials,&nbsp;slipped past security controls, impersonated a trusted user, and gained access to critical systems. In other cases, similar intrusions delayed paychecks, rerouted invoices,&nbsp;stole sensitive data, locked up&nbsp;entire&nbsp;networks,&nbsp;interrupted patient care, and strained already tight budgets at schools...
The post Defending the gates: How a global coalition disrupted Tycoon 2FA, a major driver of initial access and large-scale online impersonation appeared first on Microsoft On the Issues. ]]></description>
<link>https://tsecurity.de/de/3325775/IT+Sicherheit/Cybersecurity+Nachrichten/Defending+the+gates%3A+How+a+global+coalition+disrupted+Tycoon+2FA%2C+a+major+driver+of+initial+access+and+large-scale+online+impersonation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325775/IT+Sicherheit/Cybersecurity+Nachrichten/Defending+the+gates%3A+How+a+global+coalition+disrupted+Tycoon+2FA%2C+a+major+driver+of+initial+access+and+large-scale+online+impersonation/</guid>
<pubDate>Wed, 04 Mar 2026 17:00:06 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2FAS Authenticator: Update bringt verbesserte Verschlüsselung für iCloud-Backups]]></title> 
<description><![CDATA[Wer unter iOS auf der Suche nach einer Open-Source-Alternative zum Google Authenticator oder anderen Apps ist, d&uuml;rfte schon einmal &uuml;ber 2FAS gestolpert sein (wir stellten das Tool bereits vor Jahren vor). Die Entwickler haben nun ein Update auf Version 5.4.0...Zum Beitrag: 2FAS Authenticator: Update bringt verbesserte Verschl&uuml;sselung f&uuml;r iCloud-Backups

 ]]></description>
<link>https://tsecurity.de/de/3325520/IT+Nachrichten/2FAS+Authenticator%3A+Update+bringt+verbesserte+Verschl%C3%BCsselung+f%C3%BCr+iCloud-Backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325520/IT+Nachrichten/2FAS+Authenticator%3A+Update+bringt+verbesserte+Verschl%C3%BCsselung+f%C3%BCr+iCloud-Backups/</guid>
<pubDate>Wed, 04 Mar 2026 14:00:29 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2FAS: iCloud Backup mit Passwortschutz]]></title> 
<description><![CDATA[Die iOS-App des 2FA-Authentifizierungsprogramms 2FAS wird aktuell in neuer Version verteilt. In dieser ist der Passwortschutz f&uuml;r das iCloud Backup enthalten. 2FAS habe ich im Blog schon h&auml;ufig erw&auml;hnt. Es &hellip; ]]></description>
<link>https://tsecurity.de/de/3324326/IT+Downloads/2FAS%3A+iCloud+Backup+mit+Passwortschutz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324326/IT+Downloads/2FAS%3A+iCloud+Backup+mit+Passwortschutz/</guid>
<pubDate>Wed, 04 Mar 2026 07:41:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16]]></title> 
<description><![CDATA[Oblivion: Neuer Android-RAT ab 300 Dollar umgeht Sicherheitsabfragen bis Android 16 und kapert Smartphones per Hidden VNC.
Der Artikel Oblivion Android RAT: Kapert SMS, 2FA und umgeht Schutzmechanismen bis Android 16 erschien zuerst auf TARNKAPPE.INFO ]]></description>
<link>https://tsecurity.de/de/3318153/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Oblivion+Android+RAT%3A+Kapert+SMS%2C+2FA+und+umgeht+Schutzmechanismen+bis+Android+16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3318153/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Oblivion+Android+RAT%3A+Kapert+SMS%2C+2FA+und+umgeht+Schutzmechanismen+bis+Android+16/</guid>
<pubDate>Sun, 01 Mar 2026 15:40:21 +0100</pubDate>
</item>
<item> 
<title><![CDATA[MalwareBazaar | SHA256 63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390 (WalkLoader)]]></title> 
<description><![CDATA[

    2026-02-24 &bull; abuse.ch
     &bull; abuse.ch
     &bull; elf.walkloader
    
    
    Open article on Malpedia
 ]]></description>
<link>https://tsecurity.de/de/3309948/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/MalwareBazaar+%7C+SHA256+63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390+%28WalkLoader%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309948/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/MalwareBazaar+%7C+SHA256+63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390+%28WalkLoader%29/</guid>
<pubDate>Wed, 25 Feb 2026 15:32:03 +0100</pubDate>
</item>
<item> 
<title><![CDATA[2FA-App Aegis Authenticator: Neue Version 3.4.2 mit Verbesserungen]]></title> 
<description><![CDATA[In unserem Blog haben wir bereits mehrfach OTP-Apps behandelt. Die meisten Passwortmanager bieten mittlerweile die M&ouml;glichkeit, OTP-Codes zu generieren, allerdings nicht alle. Viele Nutzer bevorzugen es zudem, Benutzernamen und Passw&ouml;rter von den Einmal-Passw&ouml;rtern zu trennen, um das Risiko eines vollst&auml;ndigen...Zum Beitrag: 2FA-App Aegis Authenticator: Neue Version 3.4.2 mit Verbesserungen

 ]]></description>
<link>https://tsecurity.de/de/3308956/IT+Nachrichten/2FA-App+Aegis+Authenticator%3A+Neue+Version+3.4.2+mit+Verbesserungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3308956/IT+Nachrichten/2FA-App+Aegis+Authenticator%3A+Neue+Version+3.4.2+mit+Verbesserungen/</guid>
<pubDate>Wed, 25 Feb 2026 07:30:59 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Verlasst euch nicht allein auf Passwortmanager.. #cybersecurity #passwortmanager #2fa]]></title> 
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:16  ]]></description>
<link>https://tsecurity.de/de/3307316/IT+Reverse+Engineering/Video/Verlasst+euch+nicht+allein+auf+Passwortmanager..+%23cybersecurity+%23passwortmanager+%232fa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3307316/IT+Reverse+Engineering/Video/Verlasst+euch+nicht+allein+auf+Passwortmanager..+%23cybersecurity+%23passwortmanager+%232fa/</guid>
<pubDate>Tue, 24 Feb 2026 14:44:49 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data]]></title> 
<description><![CDATA[A malicious Chrome extension that claims to help Meta Business users quietly&nbsp;steals Facebook Business Manager 2FA codes and analytics data, putting high‑value ad accounts at risk of takeover. The extension, &ldquo;CL Suite by @CLMasters&rdquo; (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in&hellip;
Read more &rarr;
The post Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3292627/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Steals+Facebook+Business+Manage+2FA+Codes+and+Analytics+Data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3292627/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Steals+Facebook+Business+Manage+2FA+Codes+and+Analytics+Data/</guid>
<pubDate>Tue, 17 Feb 2026 09:34:22 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data]]></title> 
<description><![CDATA[A malicious Chrome extension that claims to help Meta Business users quietly&nbsp;steals Facebook Business Manager 2FA codes and analytics data, putting high‑value ad accounts at risk of takeover. The extension, &ldquo;CL Suite by @CLMasters&rdquo; (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web Store and specifically targets Meta Business Suite and Facebook Business Manager environments. [&hellip;]
The post Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3292582/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Steals+Facebook+Business+Manage+2FA+Codes+and+Analytics+Data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3292582/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Steals+Facebook+Business+Manage+2FA+Codes+and+Analytics+Data/</guid>
<pubDate>Tue, 17 Feb 2026 08:42:44 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Malicious Chrome Extension Exposes Facebook Business Manager Accounts to 2FA and Analytics Theft]]></title> 
<description><![CDATA[A malicious Google Chrome extension,&nbsp;CL Suite by @CLMasters, which masquerades as a productivity tool for Meta Business Suite while silently stealing sensitive authentication data. Although the extension markets itself as a solution to &ldquo;remove verification popups&rdquo; and &ldquo;generate 2FA codes,&rdquo;&hellip;
Read more &rarr;
The post Malicious Chrome Extension Exposes Facebook Business Manager Accounts to 2FA and Analytics Theft appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3292467/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Exposes+Facebook+Business+Manager+Accounts+to+2FA+and+Analytics+Theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3292467/IT+Sicherheit/Cybersecurity+Nachrichten/Malicious+Chrome+Extension+Exposes+Facebook+Business+Manager+Accounts+to+2FA+and+Analytics+Theft/</guid>
<pubDate>Tue, 17 Feb 2026 08:11:37 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Meta Business Admins Exposed by 2FA-Harvesting Chrome Extension]]></title> 
<description><![CDATA[A fake Meta Business Chrome extension stole 2FA secrets to hijack accounts. The post Meta Business Admins Exposed by 2FA-Harvesting Chrome Extension appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Meta&hellip;
Read more &rarr;
The post Meta Business Admins Exposed by 2FA-Harvesting Chrome Extension appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3291339/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Business+Admins+Exposed+by+2FA-Harvesting+Chrome+Extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3291339/IT+Sicherheit/Cybersecurity+Nachrichten/Meta+Business+Admins+Exposed+by+2FA-Harvesting+Chrome+Extension/</guid>
<pubDate>Mon, 16 Feb 2026 15:34:51 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Tycoon 2FA Campaign Abusing *.contractors Domains for Gmail and Microsoft 365 Credential Harvesting]]></title> 
<description><![CDATA[Overview Over the past few weeks, I have been tracking a credential harvesting campaign that repeatedly abuses newly registered *.contractors domains to deliver Gmail and Microsoft 365/Outlook phishing pages. While the social engineering lures vary including ICANN email verification, document sharing, and account security prompts. The underlying infrastructure, tooling, and execution flow remain consistent Based [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3288672/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Tycoon+2FA+Campaign+Abusing+%2A.contractors+Domains+for+Gmail+and+Microsoft+365+Credential+Harvesting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3288672/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Tycoon+2FA+Campaign+Abusing+%2A.contractors+Domains+for+Gmail+and+Microsoft+365+Credential+Harvesting/</guid>
<pubDate>Thu, 29 Jan 2026 00:12:07 +0100</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-64175 | Gogs up to 0.13.3 2FA Recovery Code Validation improper authentication (GHSA-p6x6-9mx6-26wj / WID-SEC-2026-0338)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Gogs up to 0.13.3. This impacts an unknown function of the component 2FA Recovery Code Validation. Executing a manipulation can lead to improper authentication.

This vulnerability is handled as CVE-2025-64175. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3277017/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-64175+%7C+Gogs+up+to+0.13.3+2FA+Recovery+Code+Validation+improper+authentication+%28GHSA-p6x6-9mx6-26wj+%2F+WID-SEC-2026-0338%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3277017/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-64175+%7C+Gogs+up+to+0.13.3+2FA+Recovery+Code+Validation+improper+authentication+%28GHSA-p6x6-9mx6-26wj+%2F+WID-SEC-2026-0338%29/</guid>
<pubDate>Mon, 09 Feb 2026 11:54:57 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Signify moves 2FA onto Android smartphones and tablets]]></title> 
<description><![CDATA[Signify has enabled its software token two-factor authentication (2FA) service as an Android app, making the company one of the first to extend 2FA to the Google smartphone platform. The Android app joins similar apps available for the BlackBerry, iPhone and iPad platforms. ]]></description>
<link>https://tsecurity.de/de/3270822/IT+Sicherheit/Cybersecurity+Nachrichten/Signify+moves+2FA+onto+Android+smartphones+and+tablets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3270822/IT+Sicherheit/Cybersecurity+Nachrichten/Signify+moves+2FA+onto+Android+smartphones+and+tablets/</guid>
<pubDate>Fri, 15 Jul 2011 13:48:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Dropbox Aims to Thwart Phishers with 2FA Security Keys]]></title> 
<description><![CDATA[Support for USB log-in keys should encourage secure authentication ]]></description>
<link>https://tsecurity.de/de/3267767/IT+Sicherheit/Cybersecurity+Nachrichten/Dropbox+Aims+to+Thwart+Phishers+with+2FA+Security+Keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3267767/IT+Sicherheit/Cybersecurity+Nachrichten/Dropbox+Aims+to+Thwart+Phishers+with+2FA+Security+Keys/</guid>
<pubDate>Thu, 13 Aug 2015 11:10:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Sony Finally Implements 2FA for PlayStation Network]]></title> 
<description><![CDATA[5 years after a data breach affected 77 million people, Sony implements two-factor authentication for the PlayStation Network. ]]></description>
<link>https://tsecurity.de/de/3267135/IT+Sicherheit/Cybersecurity+Nachrichten/Sony+Finally+Implements+2FA+for+PlayStation+Network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3267135/IT+Sicherheit/Cybersecurity+Nachrichten/Sony+Finally+Implements+2FA+for+PlayStation+Network/</guid>
<pubDate>Mon, 25 Apr 2016 19:27:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Adaptive Authentication on the Rise as 2FA Fervor Wanes]]></title> 
<description><![CDATA[Those who use two-factor authentication (2FA) admit that they receive complaints about it from their users. ]]></description>
<link>https://tsecurity.de/de/3266472/IT+Sicherheit/Cybersecurity+Nachrichten/Adaptive+Authentication+on+the+Rise+as+2FA+Fervor+Wanes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266472/IT+Sicherheit/Cybersecurity+Nachrichten/Adaptive+Authentication+on+the+Rise+as+2FA+Fervor+Wanes/</guid>
<pubDate>Thu, 12 Jan 2017 21:08:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Mobile Hackers Intercept Bank 2FA to Drain Accounts]]></title> 
<description><![CDATA[Known bug in global SS7 protocol is to blame ]]></description>
<link>https://tsecurity.de/de/3266189/IT+Sicherheit/Cybersecurity+Nachrichten/Mobile+Hackers+Intercept+Bank+2FA+to+Drain+Accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3266189/IT+Sicherheit/Cybersecurity+Nachrichten/Mobile+Hackers+Intercept+Bank+2FA+to+Drain+Accounts/</guid>
<pubDate>Fri, 05 May 2017 11:08:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Twitter Expands 2FA Options to Third-Party Authenticator Apps]]></title> 
<description><![CDATA[Twitter fans can now use Google Authenticator, Duo Mobile, Authy, 1Password and others instead of SMS. ]]></description>
<link>https://tsecurity.de/de/3265607/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter+Expands+2FA+Options+to+Third-Party+Authenticator+Apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3265607/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter+Expands+2FA+Options+to+Third-Party+Authenticator+Apps/</guid>
<pubDate>Thu, 21 Dec 2017 20:49:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[White Hat Spoofs 2FA, Sends User to Phishing Page]]></title> 
<description><![CDATA[Renowned hacker Kevin Mitnick bypasses 2FA with relative ease. ]]></description>
<link>https://tsecurity.de/de/3265009/IT+Sicherheit/Cybersecurity+Nachrichten/White+Hat+Spoofs+2FA%2C+Sends+User+to+Phishing+Page/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3265009/IT+Sicherheit/Cybersecurity+Nachrichten/White+Hat+Spoofs+2FA%2C+Sends+User+to+Phishing+Page/</guid>
<pubDate>Fri, 11 May 2018 15:55:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Spam Click Rates High, 2FA Use Low at Work]]></title> 
<description><![CDATA[Insider threats and lack of identity management policies put organizations at risk, according to three new surveys ]]></description>
<link>https://tsecurity.de/de/3264647/IT+Sicherheit/Cybersecurity+Nachrichten/Spam+Click+Rates+High%2C+2FA+Use+Low+at+Work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264647/IT+Sicherheit/Cybersecurity+Nachrichten/Spam+Click+Rates+High%2C+2FA+Use+Low+at+Work/</guid>
<pubDate>Wed, 01 Aug 2018 14:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Reddit Breached After SMS 2FA Fail]]></title> 
<description><![CDATA[Web giant took over a month to disclose incident ]]></description>
<link>https://tsecurity.de/de/3264644/IT+Sicherheit/Cybersecurity+Nachrichten/Reddit+Breached+After+SMS+2FA+Fail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264644/IT+Sicherheit/Cybersecurity+Nachrichten/Reddit+Breached+After+SMS+2FA+Fail/</guid>
<pubDate>Thu, 02 Aug 2018 10:43:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Instagram Bids to Boost Transparency and 2FA]]></title> 
<description><![CDATA[Support for third-party authentication and response to Russian activity announced ]]></description>
<link>https://tsecurity.de/de/3264520/IT+Sicherheit/Cybersecurity+Nachrichten/Instagram+Bids+to+Boost+Transparency+and+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264520/IT+Sicherheit/Cybersecurity+Nachrichten/Instagram+Bids+to+Boost+Transparency+and+2FA/</guid>
<pubDate>Wed, 29 Aug 2018 12:41:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[2FA Login Failure in Office 365 and Azure]]></title> 
<description><![CDATA[Users worldwide have been impacted by issues with Microsoft 2FA in Office 365 and Azure ]]></description>
<link>https://tsecurity.de/de/3264160/IT+Sicherheit/Cybersecurity+Nachrichten/2FA+Login+Failure+in+Office+365+and+Azure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264160/IT+Sicherheit/Cybersecurity+Nachrichten/2FA+Login+Failure+in+Office+365+and+Azure/</guid>
<pubDate>Mon, 19 Nov 2018 16:15:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Black Friday Warning as UK Retailers Fail on 2FA]]></title> 
<description><![CDATA[LastPass claims only Amazon offers customers more secure log-ins ]]></description>
<link>https://tsecurity.de/de/3264139/IT+Sicherheit/Cybersecurity+Nachrichten/Black+Friday+Warning+as+UK+Retailers+Fail+on+2FA/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264139/IT+Sicherheit/Cybersecurity+Nachrichten/Black+Friday+Warning+as+UK+Retailers+Fail+on+2FA/</guid>
<pubDate>Fri, 23 Nov 2018 10:46:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Twitter’s New 2FA Policy Tackles SIM Swap Risk]]></title> 
<description><![CDATA[Users can sign-up for strong authentication without phone number ]]></description>
<link>https://tsecurity.de/de/3262454/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter%E2%80%99s+New+2FA+Policy+Tackles+SIM+Swap+Risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262454/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter%E2%80%99s+New+2FA+Policy+Tackles+SIM+Swap+Risk/</guid>
<pubDate>Mon, 25 Nov 2019 12:01:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zoom Adds 2FA Feature to Further Secure Platform]]></title> 
<description><![CDATA[Feature makes it easier for organizations and admins to protect users and prevent security breaches ]]></description>
<link>https://tsecurity.de/de/3260867/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+Adds+2FA+Feature+to+Further+Secure+Platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260867/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+Adds+2FA+Feature+to+Further+Secure+Platform/</guid>
<pubDate>Fri, 11 Sep 2020 12:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Twitter Updates 2FA to Enable Use of Multiple Security Keys]]></title> 
<description><![CDATA[Users will soon be able to use security keys as sole authentication method ]]></description>
<link>https://tsecurity.de/de/3259718/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter+Updates+2FA+to+Enable+Use+of+Multiple+Security+Keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3259718/IT+Sicherheit/Cybersecurity+Nachrichten/Twitter+Updates+2FA+to+Enable+Use+of+Multiple+Security+Keys/</guid>
<pubDate>Tue, 16 Mar 2021 14:15:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns]]></title> 
<description><![CDATA[Discovered by Sekoia in 2023, the kit is associated with Adversary-in-The-Middle (AiTM) attacks ]]></description>
<link>https://tsecurity.de/de/3256975/IT+Sicherheit/Cybersecurity+Nachrichten/New+Tycoon+2FA+Phishing+Kit+Raises+Cybersecurity+Concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3256975/IT+Sicherheit/Cybersecurity+Nachrichten/New+Tycoon+2FA+Phishing+Kit+Raises+Cybersecurity+Concerns/</guid>
<pubDate>Mon, 25 Mar 2024 18:30:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: 2FAS Auth – Free, open-source 2FA for iOS]]></title> 
<description><![CDATA[Online accounts usually rely on a password, but passwords alone can be weak if they&rsquo;re reused, easily guessed, or stolen. Two-factor authentication (2FA) adds a second layer of verification, usually a six-digit code generated by an app on your phone. 2FAS Auth is a free, open-source two-factor authentication app that helps users securely log in to their accounts by verifying their identity. The app doesn&rsquo;t require an account to use and is available as a &hellip; More &rarr;
The post Product showcase: 2FAS Auth &ndash; Free, open-source 2FA for iOS appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3249613/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+2FAS+Auth+%E2%80%93+Free%2C+open-source+2FA+for+iOS/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3249613/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+2FAS+Auth+%E2%80%93+Free%2C+open-source+2FA+for+iOS/</guid>
<pubDate>Tue, 03 Feb 2026 06:30:16 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Product showcase: 2FAS Auth – Free, open-source 2FA for iOS]]></title> 
<description><![CDATA[Online accounts usually rely on a password, but passwords alone can be weak if they&rsquo;re reused, easily guessed, or stolen. Two-factor authentication (2FA) adds a second layer of verification, usually a six-digit code generated by an app on your phone.&hellip;
Read more &rarr;
The post Product showcase: 2FAS Auth &ndash; Free, open-source 2FA for iOS appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3249612/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+2FAS+Auth+%E2%80%93+Free%2C+open-source+2FA+for+iOS/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3249612/IT+Sicherheit/Cybersecurity+Nachrichten/Product+showcase%3A+2FAS+Auth+%E2%80%93+Free%2C+open-source+2FA+for+iOS/</guid>
<pubDate>Tue, 03 Feb 2026 06:34:01 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities]]></title> 
<description><![CDATA[Both platforms serve as backbone infrastructure for remote work and software development, making these flaws particularly dangerous for business continuity.
The post Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities appeared first on TechRepublic. ]]></description>
<link>https://tsecurity.de/de/3228103/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Patch+RCE%2C+DoS%2C+and+2FA+Bypass+Vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3228103/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Patch+RCE%2C+DoS%2C+and+2FA+Bypass+Vulnerabilities/</guid>
<pubDate>Thu, 22 Jan 2026 12:34:24 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities]]></title> 
<description><![CDATA[Both platforms serve as backbone infrastructure for remote work and software development, making these flaws particularly dangerous for business continuity. The post Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities appeared first on TechRepublic. This article has been&hellip;
Read more &rarr;
The post Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3228013/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Patch+RCE%2C+DoS%2C+and+2FA+Bypass+Vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3228013/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Patch+RCE%2C+DoS%2C+and+2FA+Bypass+Vulnerabilities/</guid>
<pubDate>Thu, 22 Jan 2026 13:05:03 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Access WhatsApp & Gmail of Anyone & Bypass 2FA / MFA 🔓👁️]]></title> 
<description><![CDATA[Author: zSecurity - Bewertung: 49x - Views:216 Learn how the Browser in the Browser attack is used by hackers to bypass two factor and multi-factor authentications (2FA / MFA) and one time passwords (OTP). As an example the video shows how this technique is used to gain access to my own Whatsapp and Gmail accounts.

🔴 Use the code ZSECURITY to get up to 74% discount on Hostinger&#039;s VPS to host your own AI, VPN, C2 or Browser ;)👇
https://www.hostinger.com/zsecurity

---------------------------------------------------------------
All Resources and links are included in the latest post in our website, zSecurity.
---------------------------------------------------------------
⚠️ This video is made for educational purposes only, we only test devices and systems that we own or have permission to test, you should not test the security of devices that you do not own or do not have permission to test. ⚠️
---------------------------------------------------------------
🧠 Learn how to use AI for Hacking and Hack AI in my Hacking Masterclass 👇
https://zsecurity.org/courses/masterclass-membership/

🧠 My other hacking courses 👇
https://zsecurity.org/courses/
---------------------------------------------------------------
zSecurity Company - https://zsecurity.com/
Community - https://zsecurity.org/
Facebook - https://www.facebook.com/ZSecurity-1453250781458287/
Twitter - https://twitter.com/_zSecurity_
Instagram - https://www.instagram.com/zsecurity_org/
Linkedin - https://www.linkedin.com/company/zsecurity-org/
TikTok - https://www.tiktok.com/@zsecurity_org
---------------------------------------------------------------
Time Stamps:
00 - Intro
00:59 - BitB Technique 
02:34 - 1. Creating a cloud server. 
08:03 - 2. Installing a URL-accessible Browser
11:39 - 3. Configuring the Browser BitB Attack
14:10 - Installing Uncensored AI Models on the Cloud
14:27 - Launching BitB Attack
17:55 - Hacking Gmail &amp; Bypassing 2FA
24:59 - Hacking Whatsapp ]]></description>
<link>https://tsecurity.de/de/3227847/Videos/Access+WhatsApp+%26+Gmail+of+Anyone+%26+Bypass+2FA+%2F+MFA+%F0%9F%94%93%F0%9F%91%81%EF%B8%8F/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3227847/Videos/Access+WhatsApp+%26+Gmail+of+Anyone+%26+Bypass+2FA+%2F+MFA+%F0%9F%94%93%F0%9F%91%81%EF%B8%8F/</guid>
<pubDate>Thu, 22 Jan 2026 11:42:14 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws]]></title> 
<description><![CDATA[Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution.
The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia Routers (MMRs) that could permit a meeting participant to conduct remote code execution attacks. The vulnerability, tracked as CVE-2026-22844 ]]></description>
<link>https://tsecurity.de/de/3226325/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Release+Security+Updates+Fixing+RCE%2C+DoS%2C+and+2FA+Bypass+Flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226325/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Release+Security+Updates+Fixing+RCE%2C+DoS%2C+and+2FA+Bypass+Flaws/</guid>
<pubDate>Wed, 21 Jan 2026 16:42:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws]]></title> 
<description><![CDATA[Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution. The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia Routers&hellip;
Read more &rarr;
The post Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3226322/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Release+Security+Updates+Fixing+RCE%2C+DoS%2C+and+2FA+Bypass+Flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226322/IT+Sicherheit/Cybersecurity+Nachrichten/Zoom+and+GitLab+Release+Security+Updates+Fixing+RCE%2C+DoS%2C+and+2FA+Bypass+Flaws/</guid>
<pubDate>Wed, 21 Jan 2026 17:02:44 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks]]></title> 
<description><![CDATA[Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE). The patches resolve issues ranging from high-severity authentication flaws to denial-of-service conditions affecting core platform functionality. Critical 2FA Bypass&hellip;
Read more &rarr;
The post Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3226203/IT+Sicherheit/Cybersecurity+Nachrichten/Multiple+GitLab+Vulnerabilities+Enables+2FA+Bypass+and+DoS+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226203/IT+Sicherheit/Cybersecurity+Nachrichten/Multiple+GitLab+Vulnerabilities+Enables+2FA+Bypass+and+DoS+Attacks/</guid>
<pubDate>Wed, 21 Jan 2026 16:15:18 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks]]></title> 
<description><![CDATA[Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE). The patches resolve issues ranging from high-severity authentication flaws to denial-of-service conditions affecting core platform functionality. Critical 2FA Bypass Vulnerability The most severe vulnerability is CVE-2026-0723, an unchecked return value issue in authentication services [&hellip;]
The post Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3226152/IT+Sicherheit/Cybersecurity+Nachrichten/Multiple+GitLab+Vulnerabilities+Enables+2FA+Bypass+and+DoS+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226152/IT+Sicherheit/Cybersecurity+Nachrichten/Multiple+GitLab+Vulnerabilities+Enables+2FA+Bypass+and+DoS+Attacks/</guid>
<pubDate>Wed, 21 Jan 2026 15:51:28 +0100</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,17ms -->