MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage

2026-07-05T19:24:00Z9f50111000e976b2ff3625cfbb4e93a1f06ece9b91c8aa254c180af8625b3dba
AI/LLM securityAdaptHealthCISA KEVCisco vulnerabilitiesEvilTokensFBIGoogleMedtronicMiasma campaignNetNutOracle E-Business SuiteSharePoint RCEagentic ransomwareattested TLSbanking securitybotnetconfidential computingdata breachdevice-code phishinghealthcare datain-browser ransomwaremulti-factor authenticationnpm supply-chainprompt injectionransomware

What happened

A cluster of high-impact incidents and emerging threats: banks weakening MFA policies for convenience, multiple critical vulnerabilities being actively exploited (including SharePoint RCE additions to CISA's KEV and Cisco issues such as CVE-2026-20230), and attackers abusing third parties to steal health and payroll data (AdaptHealth, Medtronic, Nissan/PeopleSoft). Law-enforcement/industry takedowns and investigations impacted large botnets and proxy services (NetNut), while criminals and researchers are weaponizing AI and tooling — from device-code phishing kits (EvilTokens) and agentic/in‑in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
9f50111000e976b2ff3625cfbb4e93a1f06ece9b91c8aa254c180af8625b3dba
Enrichment time
2026-07-05T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.