<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #MFA Bypass</title><description>Cybersecurity articles tagged #MFA Bypass on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>New JWR Phishing Framework Bypasses MFA with Live Monitoring</title><link>https://runtimerebel.com/blog/new-jwr-phishing-framework-bypasses-mfa-with-live-monitoring</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-jwr-phishing-framework-bypasses-mfa-with-live-monitoring</guid><description>JWR, a new real-time phishing framework, uses WebSockets to bypass MFA and steal sensitive data via SMS lures, posing a critical threat.</description><pubDate>Fri, 14 Aug 2026 01:09:15 GMT</pubDate><category>Phishing</category><category>Smishing</category><category>MFA Bypass</category><category>JWR</category><category>The Outsider</category></item><item><title>Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse</title><link>https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</guid><description>Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.</description><pubDate>Sat, 08 Aug 2026 00:57:13 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>Ransomware</category><category>Microsoft 365</category><category>UAT 11764</category></item><item><title>Greatness PhaaS Adds Device Code Phishing for MFA Bypass</title><link>https://runtimerebel.com/blog/greatness-phaas-adds-device-code-phishing-for-mfa-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/greatness-phaas-adds-device-code-phishing-for-mfa-bypass</guid><description>Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.</description><pubDate>Tue, 04 Aug 2026 17:30:11 GMT</pubDate><category>PhaaS</category><category>MFA Bypass</category><category>OAuth 2 0</category><category>Microsoft 365</category><category>Greatness</category></item><item><title>Securing Critical Infrastructure: Closing Identity Gaps</title><link>https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</guid><description>Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.</description><pubDate>Tue, 21 Jul 2026 17:24:12 GMT</pubDate><category>Critical Infrastructure</category><category>Identity Security</category><category>Zero Trust</category><category>Credential Theft</category><category>MFA Bypass</category><category>Supply Chain Attack</category><category>Phishing</category></item><item><title>Identity Attacks &amp; MFA Bypass: The New Ransomware Entry Point</title><link>https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</guid><description>Identity-based attacks, particularly email phishing, are now the leading cause of ransomware infections.</description><pubDate>Wed, 15 Jul 2026 21:10:35 GMT</pubDate><category>Ransomware</category><category>Identity Attacks</category><category>MFA Bypass</category><category>Phishing</category><category>Credential Theft</category><category>Initial Access</category></item><item><title>Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits</title><link>https://runtimerebel.com/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits</link><guid isPermaLink="true">https://runtimerebel.com/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits</guid><description>A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker&apos;s toolkit and session cookies.</description><pubDate>Mon, 13 Jul 2026 11:18:10 GMT</pubDate><category>Evilginx</category><category>Microsoft 365</category><category>Phishing</category><category>AitM</category><category>MFA Bypass</category></item><item><title>ARToken PhaaS Exposes EvilTokens&apos; M365 Phishing Toolkit</title><link>https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</link><guid isPermaLink="true">https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</guid><description>ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.</description><pubDate>Fri, 03 Jul 2026 17:28:05 GMT</pubDate><category>ARToken</category><category>EvilTokens</category><category>PhaaS</category><category>Phishing</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Credential Harvesting</category><category>Threat Intelligence</category></item><item><title>Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering</title><link>https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</guid><description>An alleged Scattered Spider member&apos;s extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…</description><pubDate>Thu, 02 Jul 2026 10:45:17 GMT</pubDate><category>Scattered Spider</category><category>Social Engineering</category><category>MFA Bypass</category><category>Ransomware</category><category>Cybercrime</category><category>Extradition</category><category>UNC3944</category><category>0ktapus</category></item><item><title>Kali365 Phishing-as-a-Service Expands to Target AWS and Okta</title><link>https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</link><guid isPermaLink="true">https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</guid><description>The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.</description><pubDate>Wed, 03 Jun 2026 05:44:29 GMT</pubDate><category>Kali365</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Cloud Security</category><category>AWS</category><category>Okta</category></item><item><title>Dashlane Brute-Force Attack: Mitigation for Stolen Encrypted Vaults</title><link>https://runtimerebel.com/blog/dashlane-brute-force-attack-mitigation-for-stolen-encrypted-vaults</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-brute-force-attack-mitigation-for-stolen-encrypted-vaults</guid><description>Dashlane confirms a brute-force attack where fewer than 20 personal vaults were downloaded. Analyze the technical impact and mitigation strategies for users.</description><pubDate>Tue, 02 Jun 2026 05:40:26 GMT</pubDate><category>Dashlane</category><category>Brute Force</category><category>Password Manager</category><category>Identity Theft</category><category>MFA Bypass</category></item><item><title>FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts</title><link>https://runtimerebel.com/blog/fbi-warns-of-kali365-phaas-targeting-microsoft-365-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-of-kali365-phaas-targeting-microsoft-365-accounts</guid><description>The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.</description><pubDate>Mon, 25 May 2026 13:18:04 GMT</pubDate><category>Kali365</category><category>Microsoft 365</category><category>PhaaS</category><category>Oauth Abuse</category><category>MFA Bypass</category></item><item><title>Chinese-Language PhaaS: Real-Time OTP Interception and Tokenization</title><link>https://runtimerebel.com/blog/chinese-language-phaas-real-time-otp-interception-and-tokenization</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-language-phaas-real-time-otp-interception-and-tokenization</guid><description>Chinese-language PhaaS providers like Darcula are shifting to real-time OTP interception and digital wallet tokenization to bypass modern MFA controls.</description><pubDate>Mon, 25 May 2026 05:38:17 GMT</pubDate><category>PhaaS</category><category>UNC5814</category><category>Darcula</category><category>MFA Bypass</category><category>Tokenization</category><category>YY Lai Yu</category></item><item><title>SonicWall Gen6 SSL-VPN MFA Bypass: Incomplete Patching Leads to Compromise</title><link>https://runtimerebel.com/blog/sonicwall-gen6-ssl-vpn-mfa-bypass-incomplete-patching-leads-to-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-gen6-ssl-vpn-mfa-bypass-incomplete-patching-leads-to-compromise</guid><description>Hackers are bypassing MFA on SonicWall Gen6 SSL-VPN appliances via brute-force due to incomplete patching, enabling ransomware tool deployment.</description><pubDate>Thu, 21 May 2026 00:58:49 GMT</pubDate><category>SonicWall</category><category>MFA Bypass</category><category>VPN</category><category>Brute Force</category><category>Ransomware</category></item><item><title>Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec</title><link>https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</guid><description>Analysis of Tycoon 2FA&apos;s declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.</description><pubDate>Sat, 18 Apr 2026 12:18:24 GMT</pubDate><category>Tycoon 2FA</category><category>Dadsec</category><category>Phishing as a Service</category><category>AitM</category><category>MFA Bypass</category></item><item><title>Detecting Credential-Based Attacks: Moving Beyond Signatures</title><link>https://runtimerebel.com/blog/detecting-credential-based-attacks-moving-beyond-signatures</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-credential-based-attacks-moving-beyond-signatures</guid><description>Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.</description><pubDate>Fri, 10 Apr 2026 20:14:30 GMT</pubDate><category>Identity Security</category><category>Credential Theft</category><category>Behavioral Analytics</category><category>MFA Bypass</category><category>ITDR</category></item><item><title>Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers</title><link>https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</guid><description>Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.</description><pubDate>Mon, 06 Apr 2026 16:21:46 GMT</pubDate><category>Infostealers</category><category>Session Hijacking</category><category>Credential Harvesting</category><category>MFA Bypass</category></item><item><title>OAuth 2.0 Device Code Phishing Surge: Protecting M365 and Google</title><link>https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-surge-protecting-m365-and-google</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-surge-protecting-m365-and-google</guid><description>Device code phishing attacks have surged 37x this year. Learn how adversaries abuse the OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts.</description><pubDate>Sat, 04 Apr 2026 16:14:53 GMT</pubDate><category>OAuth 2 0</category><category>Phishing</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Account Takeover</category></item><item><title>EvilTokens Fuels Microsoft Device Code Phishing &amp; BEC</title><link>https://runtimerebel.com/blog/eviltokens-fuels-microsoft-device-code-phishing-bec</link><guid isPermaLink="true">https://runtimerebel.com/blog/eviltokens-fuels-microsoft-device-code-phishing-bec</guid><description>New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.</description><pubDate>Wed, 01 Apr 2026 20:19:20 GMT</pubDate><category>EvilTokens</category><category>Microsoft</category><category>Device Code Phishing</category><category>BEC</category><category>Account Takeover</category><category>Phishing</category><category>MFA Bypass</category></item><item><title>Beyond MFA: Bridging the Zero Trust Gap in Session Security</title><link>https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</guid><description>Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.</description><pubDate>Tue, 24 Mar 2026 16:29:03 GMT</pubDate><category>Zero Trust</category><category>MFA Bypass</category><category>Session Hijacking</category><category>Identity Security</category><category>Device Trust</category></item><item><title>Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure</title><link>https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</guid><description>Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.</description><pubDate>Mon, 23 Mar 2026 12:24:24 GMT</pubDate><category>Tycoon 2FA</category><category>AitM</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Credential Theft</category></item><item><title>2025 Identity Threat Report: Analyzing the Infostealer Economy</title><link>https://runtimerebel.com/blog/2025-identity-threat-report-analyzing-the-infostealer-economy</link><guid isPermaLink="true">https://runtimerebel.com/blog/2025-identity-threat-report-analyzing-the-infostealer-economy</guid><description>Recorded Future&apos;s 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.</description><pubDate>Mon, 16 Mar 2026 16:31:44 GMT</pubDate><category>Infostealer</category><category>Credential Theft</category><category>Session Hijacking</category><category>Recorded Future</category><category>MFA Bypass</category></item><item><title>Europol Dismantles Tycoon 2FA Phishing Platform: Mitigating MFA Bypass</title><link>https://runtimerebel.com/blog/europol-dismantles-tycoon-2fa-phishing-platform-mitigating-mfa-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/europol-dismantles-tycoon-2fa-phishing-platform-mitigating-mfa-bypass</guid><description>Europol and cybersecurity vendors dismantle Tycoon 2FA, a major phishing-as-a-service platform known for its sophisticated MFA bypass capabilities.</description><pubDate>Fri, 06 Mar 2026 00:40:08 GMT</pubDate><category>Tycoon 2FA</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Europol</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</guid><description>Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.</description><pubDate>Thu, 05 Mar 2026 08:16:06 GMT</pubDate><category>Tycoon 2FA</category><category>Europol</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category></item><item><title>Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</guid><description>International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.</description><pubDate>Wed, 04 Mar 2026 20:15:37 GMT</pubDate><category>Tycoon 2FA</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category><category>Europol</category></item><item><title>Phishing Campaign Leverages Fake Google PWA to Steal Credentials, MFA</title><link>https://runtimerebel.com/blog/phishing-campaign-leverages-fake-google-pwa-to-steal-credentials-mfa</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-campaign-leverages-fake-google-pwa-to-steal-credentials-mfa</guid><description>A sophisticated phishing campaign uses a fake Google Security PWA to compromise accounts, steal MFA codes, and proxy traffic. Learn how to protect.</description><pubDate>Tue, 03 Mar 2026 00:36:21 GMT</pubDate><category>Phishing</category><category>PWA</category><category>MFA Bypass</category><category>Credential Theft</category><category>Google Accounts</category><category>Account Takeover</category></item><item><title>Starkiller Phishing-as-a-Service: Technical Analysis of Adversary-in-the-Middle Frameworks</title><link>https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</link><guid isPermaLink="true">https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</guid><description>An examination of the Starkiller phishing platform, which employs transparent reverse proxy techniques to relay authentication traffic and capture multi-factor…</description><pubDate>Mon, 23 Feb 2026 08:20:40 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>AitM</category><category>PhaaS</category><category>Credential Theft</category></item></channel></rss>