Skip to main content
LiveListen now5 listening
Live

aired speech / station archive

MFA Bypass Evolved and npm Supply Chain Worms in 2026 [Prime Cyber Insights]

Spoken by Neural Newscast on Neural Newscast. Aired Aug 5, 01:42 PM / 267s / music_show / audio on file.

MFA Bypass Evolved and npm Supply Chain Worms in 2026 [Prime Cyber Insights]

Welcome to Prime Cyber Insights. We begin today with the professionalization of identity theft. The Greatness phishing-as-a-service platform has officially added device code phishing to its operator panel, specifically designed to bypass multi-factor authentication by abusing the OAuth two.zero Device Authorization Grant. It is a direct escalation in how attackers are weaponizing legitimate cloud workflows to seize control of Microsoft 365, iCloud, and Google Workspace accounts. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Aaron, the commercial side of this is what stands out. ZeroBEC reports the Greatness subscription has climbed to 289 dollars a month, and the lures are getting hyper-targeted. We’re seeing spoofed RingCentral voicemail notifications that actually bypass email gateways by exploiting safe sender exclusions. Because the target is an actual RingCentral customer, the email lands in the inbox despite failing SPF and DMARC checks. Once the agent enters a code on what looks like a genuine Microsoft page, the attacker captures the session token and enumerates the entire M365 resource set. <br/><i>acting_description:</i> analytical, observant, measured <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 It’s a cleaner path for the attacker because there's no fake login site to build or get blocked. Moving to the software supply chain, we are tracking a massive poisoning event dubbed ChainDrop. Researchers at Aikido have identified over 1,300 npm packages infected with a variant of the Shai-Hulud worm. This includes popular libraries like Keyv and Cacheable, which facilitate billions of monthly downloads. The malware exfiltrates developer and cloud credentials directly to a public GitHub repository. <br/><i>acting_description:</i> technical, authoritative, direct <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Aaron, that npm compromise is compounded by new data from GitGuardian regarding n8n. They found 321 live instances of the automation platform accepting API tokens exposed in public GitHub commits. In controlled tests, researchers were able to exfiltrate raw credentials from n8n's store without exploiting a single software vulnerability. Automation platforms are high-value targets because they sit at the center of an organization's integrations—one leaked token provides a path to everything from databases to cloud environments. <br/><i>acting_description:</i> responsive, precise, alert <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Exactly, Lauren. The blast radius for these integration platforms is enormous. Meanwhile, in critical infrastructure, Angola’s dominant telco, Unitel, is still recovering from a malicious cyberattack that hit just hours before its public offering on July 28th. While they’ve restored 2G and 3G services, the 4G and 5G networks are still facing disruptions. It highlights how tight budgets in emerging markets can lead to insufficient network segmentation, making recovery a multi-day ordeal. <br/><i>acting_description:</i> confident, structured, analytical <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Aaron, that resilience issue isn't limited to telcos. Securonix just detailed the Smoke-Screen campaign, where threat actors are abusing the legitimate ScreenConnect RMM tool for persistent access. They are rotating payloads between individual download sessions to evade hash-based detection. They’ve even been seen using Dropbox for reputation and Cloudflare tunnels for anonymity. When a properly signed service like ScreenConnect is the backdoor, traditional signature-based controls are effectively blind. <br/><i>acting_description:</i> insightful, serious, measured <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Which brings us back to the human element. Even as Google reports 800 million accounts using passkeys, researchers have demonstrated 'Pass-ta-key' attacks that can hijack accounts through Google Password Manager if the local machine is compromised. The technology is phishing-resistant, but the software implementation still has gaps that malware can exploit. Lauren, how should teams be adjusting their controls? <br/><i>acting_description:</i> guiding, balanced, professional <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Aaron, the immediate move is auditing OAuth device code flows. If you don't need the device authorization grant, block it globally via Conditional Access Policies. For RMM tools like ScreenConnect, practitioners must implement behavioral detections that flag msiexec launching with silent flags or ScreenConnect connecting to raw IP addresses. We have to stop looking for malware and start looking for the unauthorized use of legitimate tools. <br/><i>acting_description:</i> practical, focused, engaged <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 Direct and actionable. That concludes today’s briefing for Prime Cyber Insights. <br/><i>acting_description:</i> decisive

Read disclosure