MFA did exactly what it was designed to do this week. Attackers stole the session cookie anyway, ~48% success rate across 4,500+ targeted orgs. Plus: AI agents cracked 85 accounts across 21 govt systems in just 4 days. This week's roundup:
The most damaging breaches rarely flow through the vendors you worry about most.
They flow through the ones you trust most deeply. Our CEO @FrancisDinha in Forbes on why depth of access and depth of scrutiny move in opposite directions:
Migrating to Entra ID auth on Azure Point-to-Site VPN? It's only supported on the OpenVPN tunnel type — SSTP and IKEv2 don't get it. If Entra ID is the goal, you're already headed toward the OpenVPN protocol.
What that migration path actually looks like →