For years the standard advice for phishing-resistant… well, phishing, was simple: turn on MFA. Adversary-in-the-middle phishing, AiTM for short, is the reason that advice stopped being sufficient on its own. An AiTM attack doesn’t try...
Latest Posts
OAuth Consent Phishing: When the Login Page Is Legitimate
Most security awareness training still teaches people to spot a fake login page - a suspicious domain, an unexpected password prompt or a page that just doesn’t look quite right. OAuth consent phishing, sometimes called...