Skip to main content
LiveListen now5 listening
Live

aired speech / station archive

Microsoft Retires SMS MFA Amid AI Phishing Surge [Prime Cyber Insights]

Spoken by Neural Newscast on Neural Newscast. Aired Aug 13, 01:45 PM / 239s / music_show / audio on file.

Microsoft Retires SMS MFA Amid AI Phishing Surge [Prime Cyber Insights]

Welcome to the briefing room for August 13th, 2026. I'm Aaron Cole. We’re starting with a massive shift in the identity landscape that every IT admin needs to track immediately. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 I'm Lauren Mitchell. Microsoft has officially put a timer on legacy multi-factor authentication. By February 1st, 2027, they will fully retire SMS and voice-based authentication for Entra ID. This isn't just a suggestion, Aaron—passkeys are becoming mandatory for every tenant. <br/><i>acting_description:</i> engaged, clear, poised <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.3 The rationale is strictly tactical, Lauren. Microsoft cites a surge in AI-powered phishing and simplified SIM swapping. AI has lowered the barrier for attackers to manipulate voice channels and move phone numbers to controlled SIMs. Starting September 1st, Entra users will be prompted to set up those passkeys during sign-in. <br/><i>acting_description:</i> analytical, direct, calm <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 It’s a necessary pivot, Aaron, especially as we look at what Lazarus is doing. This week, we’ve confirmed they’ve been exploiting a Windows zero-day—CVE 2026 68820—since early July. It’s a use-after-free vulnerability in the WinSock driver that allows local privilege escalation to SYSTEM level, specifically targeting Windows eleven builds 26100 and 26200. <br/><i>acting_description:</i> thoughtful, responsive, objective <i>speed:</i> 0.95 <i>trailing_silence:</i> 0.4 Lazarus is using that zero-day in their 'Operation Dream Job' campaign, hitting defense and aerospace firms in Europe and India. At the same time, we're tracking a mercenary group called Jewelbug. Symantec researchers found them switching between state espionage and cryptocurrency theft from the same custom control panel, X-G-Web. <br/><i>acting_description:</i> authoritative, precise, firm <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 That Jewelbug operation is fascinating because of its scale, Aaron. They’ve managed 44 content management servers to boost fake crypto exchanges while simultaneously compromising government and military agencies in Asia and the Middle East. It shows the lines between financially motivated crime and state-aligned intelligence are almost non-existent now. <br/><i>acting_description:</i> informed, composed, observant <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Switching to the logistics sector, Uber Freight confirmed Wednesday that it’s investigating a data security incident. The Helix extortion group—a brand linked to the UNC6671 cluster—claims to have stolen nearly one million files from mailboxes and OneDrive. Google’s intelligence group notes these operators heavily favor vishing to gain their initial foothold. <br/><i>acting_description:</i> systematic, neutral, structured <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 Vishing and smishing are clearly the primary vectors this month. Surfshark launched a real-time protection tool today to address the smishing epidemic, as Americans are now facing 19 billion spam texts monthly. This follows the discovery of WindRelay, a malware combo that uses N-F-C relay and remote access trojans to authorize fraudulent payments in as little as 13 minutes. <br/><i>acting_description:</i> alert, technical, analytical <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Before we wrap, we have to mention Adobe Commerce. Yesterday, a critical vulnerability, CVE 2026 71362, was disclosed that allows attackers to hijack customer accounts by switching sessions without authentication. Sansec is already seeing exploitation attempts in the wild. If you’re running Magento or Adobe Commerce, that August security update is a priority. <br/><i>acting_description:</i> serious, concise, focused <i>speed:</i> 0.96 <i>trailing_silence:</i> 0.4 The takeaway today is clear: the speed of identity-based attacks, whether through smishing or zero-days, is compressing the defensive window. This has been Prime Cyber Insights. I'm Lauren Mitchell. Remember, this briefing is for informational purposes

Read disclosure