July 4, 2024, 12:40 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Twilio has warned users of the Authy multi-factor authentication (MFA) app about an incident in which cybercriminals may have obtained their phone numbers.


Twilio said the cybercriminals abused an unsecured Application Programming Interface (API) endpoint to verify the phone numbers of millions of Authy multi-factor authentication users.


Authy is an app that you install on your device which then produces a MFA code for you when logging into services.


The cybercriminals were able test the validity of an …

api app application application programming interface authentication authy cybercriminals endpoint factor incident interface may mfa millions multi-factor multi-factor authentication numbers phone phone numbers programming twilio unsecured verify

Cyber Security Project Engineer

@ Dezign Concepts LLC | Chantilly, VA

Cloud Cybersecurity Incident Response Lead

@ Maveris | Martinsburg, West Virginia, United States

Sr Staff Security Researcher (Malware Research - Antivirus Systems)

@ Palo Alto Networks | Santa Clara, CA, United States

Identity & Access Management, Senior Associate

@ PwC | Toronto - 18 York Street

Senior Manager, AI Security

@ Lloyds Banking Group | London 10 Gresham Street

Senior Red Team Engineer

@ Adobe | Remote California