Skip to main content
PixSnapping - steals screen pixels from Android devices

PixSnapping: The Android Exploit That Breaks 2FA

A newly published academic paper introduces a new hacker tool called PixSnapping (download PDF), an advanced attack that can steal screen pixels from Android devices and reconstruct sensitive data like 2FA codes in real time. The research demonstrates that an attacker-controlled app can capture or infer the digits displayed by authenticator apps such as Google Authenticator in under thirty seconds.

Kevin Surace
2 minute read
Cybersecurity training fails

Why Phishing Training Fails to Stop Attacks

A study from UC San Diego Health ran nearly 20,000 employees through ten simulated phishing campaigns over eight months. Training made almost no difference. Employees who had recently completed mandatory cyber awareness courses failed phishing tests at virtually the same rate as those who had not. The measured improvement was just 1.7%. More than 75% of employees spent less than a minute on the training material. Millions are spent on annual training. The phishing success rate stays the same. The lesson is clear. Training alone does not protect enterprises from phishing.

Kevin Surace
3 minute read

Microsoft ADFS Vulnerabilities and Phishing-Resistant MFA

Microsoft Active Directory Federation Services is one of the most widely deployed authentication systems in enterprise IT. Organisations use it to provide single sign-on across internal and external applications, often as a bridge between on-premises Active Directory and cloud services. It is also structurally vulnerable to a class of attack that legacy MFA cannot stop.

Kevin Surace
3 minute read
Pixel-Perfect Phishing

Pixel-Perfect Phishing Attacks and How They Bypass Legacy MFA

Phishing attacks no longer rely on obvious tells. Misspelled words, generic greetings, and suspicious domains are yesterday’s problem. Today, the most effective phishing campaigns use Unicode characters that look identical to the characters they replace. The fake URL looks real. The fake site looks real. There is nothing for the human eye or most security tools to catch. The deception happens at a level most people never inspect.

Kevin Surace
3 minute read

Ransomware Is Up 179% in 2025. Legacy MFA Is Why.

CSO Online just dropped a staggering stat: ransomware attacks have jumped 179% in the first half of 2025. Credential theft? Up 800%. That’s not a typo. Eight. Hundred. Percent.

Kevin Surace
1 minute read
CISA dropped a bombshell

CISA's Urgent Warning on Phishing-Resistant MFA and FIDO2

CISA just dropped a bombshell. In its latest alert (dated July 25, 2025), the U.S. Cybersecurity and Infrastructure Security Agency is now urging every enterprise to implement phishing-resistant multifactor authentication (MFA)—everywhere: for email, VPNs, and anything touching critical systems. Not “consider it.” Not “evaluate in the future.” Require it. Now.

Kevin Surace
1 minute read
Social Engineering Hacks Keep Winning

How Social Engineering Attacks Bypass MFA

Social engineering attacks don’t exploit software. They exploit people. An attacker who can convince a help desk agent to reset a password, or persuade an employee to approve an MFA request, bypasses every technical control in place. No vulnerability was needed. No malware was deployed. The breach happened because someone was convinced. This guide covers the most common social engineering techniques targeting enterprise authentication, how each one works in practice and why the solution is not better training.

Kevin Surace
4 minute read

The Clorox Lawsuit: 380M Over a Password

Cybersecurity Dive just reported that Clorox is suing Cognizant for $380 million after a cyberattack crippled operations. The alleged trigger? A hacker posed as an employee and convinced someone to hand over a password. That’s it. No advanced zero-day exploit. No AI-powered quantum hack. Just a social engineering phone call and a password—and now Clorox wants $380 million in damages.

Kevin Surace
1 minute read
Identity-Based Attacks

Identity-Based Attacks and How They Work

Attackers are no longer trying to break in. They are logging in. Identity-based attacks have replaced network intrusions as the dominant breach method. Firewalls, antivirus and perimeter defences are largely irrelevant when an attacker already holds valid credentials. Understanding what these attacks look like and how they work is the starting point for building authentication that can actually stop them.

Kevin Surace
2 minute read

Phishing-Proof MFA That Stops Social Engineering

Microsoft’s recent advisory on Octo Tempest should make every CISO lose sleep. This group isn’t just hacking software vulnerabilities. They’re hacking people, impersonating employees, tricking help desks into resetting passwords, stealing session cookies, and bypassing legacy MFA with social engineering.

Kevin Surace
1 minute read

AI-Generated Phishing Attacks Are Making Legacy MFA Obsolete

Generative AI just made phishing so easy that anyone can do it—and do it convincingly. According to Axios, researchers demonstrated that in just 30 seconds, a simple natural-language prompt was all it took to build a pixel-perfect spoofed login site. No coding. No technical skills. Just type “build a copy of the website login.okta.com,” and a convincing clone appears, ready to trick anyone into handing over credentials.

Kevin Surace
2 minute read
Stolen credentials are the new front door

Stolen Credentials Are the New Front Door

Attackers are not breaking in. They are logging in. Stolen credentials are now the most reliable entry point for enterprise breaches. Most defenses are built to stop an attacker trying to force their way through. The attacker who already has a valid username and password walks straight past them.

Kevin Surace
2 minute read

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.