VFF - The signal in the noise
News

MFA Stops at Login. Attackers Start There.

Read original
Share
MFA Stops at Login. Attackers Start There.

MFA successfully authenticates users at login but provides no visibility into what happens after, creating a critical blind spot that attackers exploit through lateral movement and privilege escalation. A CIO at NOV discovered this architectural gap during operational testing, finding that session token theft, not credential compromise, is the primary vector in advanced attacks. With average breach breakout time now 29 minutes and 82% of 2025 detections involving no malware, attackers have shifted to stealing legitimate credentials and session tokens rather than deploying code.

  • MFA verifies identity at login but goes blind afterward, leaving lateral movement and privilege escalation undetected
  • Session token theft is now the primary attack vector, with average breakout time at 29 minutes and fastest at 27 seconds
  • Vishing attacks rose 442% in 2024, while AI-generated phishing matches human-crafted phishing at 54% click-through rates
  • Enterprises lack rapid token revocation capabilities at the resource level, creating a gap between IAM and SecOps

MFA has become table stakes for compliance but creates a false sense of security by stopping at authentication. The real threat operates post-login through stolen session tokens, which inherit all user permissions without triggering alerts or matching signatures. This architectural blind spot means most enterprises are protected at the front door while attackers operate freely inside.

Compliance dashboards showing green MFA metrics mask active breaches happening in real time. Organizations must shift from point-in-time authentication to continuous session validation and rapid token revocation, requiring new investments in identity infrastructure and cross-team coordination between IAM and security operations.

  • Session token management and revocation must become a core security control, not an afterthought in identity architecture
  • AI-powered social engineering has commoditized credential theft, making the credential supply chain an industrial-scale threat
  • Biometric and face-based authentication alone are insufficient due to deepfake attacks, requiring layered post-authentication controls
  • The gap between IAM teams and SecOps teams is where attackers operate undetected after successful login

Monitor how enterprises implement rapid token revocation at the resource level and whether identity platforms add continuous session validation. Watch for shifts in security budgets from authentication tools toward post-authentication monitoring and lateral movement detection. Track whether regulatory frameworks begin requiring session-level controls, not just MFA compliance.

Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

Binance Enables AI Agents to Trade, Puts Safety on Users
TrendingModel Release

Binance Enables AI Agents to Trade, Puts Safety on Users

Binance has launched Agent OS, a platform that enables AI agents to execute trades on the exchange using tools like ChatGPT, Claude Code, and Cursor. The system delegates risk management and safeguards primarily to users rather than implementing centralized controls. This move opens cryptocurrency trading to autonomous AI systems while raising questions about oversight and user responsibility.

by Jagmeet Singh· TechCrunch AI
OpenAI Adds Zero Data Retention for Frontier Models

OpenAI Adds Zero Data Retention for Frontier Models

OpenAI is reaffirming its Zero Data Retention policy for eligible API customers and introducing Private Safety Processing, a new capability that enables advanced AI safety measures without storing or retaining customer data. The announcement addresses growing enterprise concerns about data privacy in AI model usage. These offerings apply to OpenAI's frontier models and are designed to serve customers with strict data governance requirements.

· OpenAI
Pennsylvania Tightens Data Center Permit Requirements

Pennsylvania Tightens Data Center Permit Requirements

Pennsylvania Governor Josh Shapiro signed an executive order on Tuesday requiring data center developers to make legally binding commitments on energy, environmental standards, and economic development before projects can proceed. The order establishes new permitting requirements that developers must satisfy to operate in the state. This represents a shift toward stricter oversight of data center expansion in Pennsylvania.

by Amir Efrati· The Information
OpenAI Launches ChatGPT for Teens With Parental Controls
TrendingModel Release

OpenAI Launches ChatGPT for Teens With Parental Controls

OpenAI has launched ChatGPT for Teens, a version of its AI assistant designed specifically for younger users with enhanced safety features, built-in protections, and parental controls. The product aims to help teens learn and think critically while using AI responsibly. The offering includes healthy-use features alongside tools that give parents additional oversight of their teen's interactions.

· OpenAI