In Cybersecurity Minute Episode 28, Chris Hughes examines the dramatic downstream effects of two-factor authentication vulnerabilities.
Highlights
00:01 — Employees at Twilio and CloudFlare were recently targeted by a massive phishing campaign, made to compromise employees’ two-factor authentication credentials.
00:31 — While Twilio and CloudFlare served as initial targets, malicious actors were able to target 130+ other organizations downstream, including DigitalOcean and DoorDash.
00:59 — The attack represents the latest effort to thwart Identity-as-a-Service provider, Okta.
01:23 — Organizations are at risk when using SaaS security and should consider integrating SaaS security management tools for increased security transparency.
02:50 — Even certain two-factor authentication practices are vulnerable to attack and downstream effects.





