Sometimes MFA isn’t enough

About a month ago we published a blog series on multi-factor authentication (MFA) by guest writer, Chris Bonatti of IECA of Casper.

Since publishing that, CISA (Cybersecurity Infrastructure Security Agency) has alerted companies that MFA was defeated in some cloud services by a combination of a brute force and pass-the-cookie attack. The video below describes what a pass-the-cookie attack is and how it works.

YouTube player

CISA said that the attacks targeted employees who accessed their organizations’ cloud services from home and weak cyber hygiene practices were the main cause behind the success of the attacks.

