
How Attackers Bypass MFA in the Real World
The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…
After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and pushed the victim to continue negotiations over an email address linked to a newly registered domain (helprans[.]com).
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
You’ve just had a ransomware scare… and then your phone rings. Someone says, “I’m Andrew, from a group of hackers.” He says your network is already compromised and tells you to email info@helprans.com to keep “negotiations” going. Same story shows up in your inbox too. Here’s the trick: INC Ransomware crews are posing as “ransomware help.” They even spun up the domain helprans.com right after attacks, just to pressure victims into talking directly to them. If anyone claims your network is hacked and wants you to email a new domain like helprans.com, hang up and immediately escalate through our internal incident process, don’t reply to them at all.

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks.…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…