RC RANDOM CHAOS

MFA bypass

4 posts

Verification became the leak
Article

Verification became the leak

An unauthorized live feed of every ID verification let attackers bypass MFA for over a year. Why readable verification output stops being proof.

MFA protects the login, not the session.
Article

MFA protects the login, not the session.

Fastpotify mints unbound session cookies that survive MFA. Stolen via AiTM or infostealer, they replay as full sessions. The telemetry that catches it.

Social engineering is a misconfiguration
Article

Social engineering is a misconfiguration

Human error in identity workflows is a misconfiguration, not incompetence - how Scattered Spider, 0ktapus and MFA fatigue exploit the validation gap.

Why MFA Alone Will Not Save You
Article

Why MFA Alone Will Not Save You

MFA stops credential stuffing but not AiTM phishing, token theft, or session hijacking. Here's what attackers actually do and how to close the gaps.