MFA Wont Stop This Phishing Kit @SecurityWeekly
MFA Wont Stop This Phishing Kit  @SecurityWeekly
Uploaded June 2026 | Updated September 2026, 2 weeks ago
The Black Site phishing kit pairs with an evasion tool called Cloaked.gg to perform adversary-in-the-middle attacks. By acting as a reverse proxy between the victim and the legitimate website, it can capture credentials and authenticated session data during the login process.

This technique targets the session itself rather than just the password, which is why traditional multi-factor authentication alone may not prevent account compromise. It also includes features intended to reduce detection by some anti-phishing technologies, raising the bar for defenders.

If your organization already uses MFA, what additional controls would help detect or stop session-hijacking phishing attacks?

Subscribe to our podcasts: securityweekly.com/subscribe

#Phishing #MFA #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
MFA Wont Stop This Phishing KitWhat Regex Cant Catch in AI SkillsSandwich Hats - PSW #937Hacking All The Devices, with AI? - Rob Allen - PSW #941Splunk Acquisition and The Blob with Allie Mellen - ESW #333Cheap AI Will Handle Most TasksInside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607AI Security Startups Are Raising INSANE Money 💰Patching Isnt Fast Enough AnymoreWhen AI Writes Production CodeAIs Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - BSW #457
Security Weekly - A CRA Resource |

MFA Won't Stop This Phishing Kit

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER