Category

phishing

7 articles

identity-security identity-security phishing opinion

MFA Fatigue Is Real — And It's Getting Worse

The Real Problem Because of course, security was brought in two weeks before go‑live. MFA fatigue isn’t a new threat—it’s the same old “click‑through” attack wrapped in a more convincing social‑engineering story. The real problem is that modern identity platforms treat MFA prompts as

Edgerunner Edgerunner 3 min read

Why Security Awareness Training Fails (and What to Do Instead)

The Real Problem Because security awareness programs are often treated like a checkbox exercise rather than an integral part of operational workflows, they inevitably fail to meaningfully reduce risk. When training sessions become disconnected from real‑world scenarios and daily tools, the knowledge gained evaporates as soon as employees return

Edgerunner Edgerunner 2 min read

The MFA Paradox: How User Frustration Is Weaponizing Security

The Real Problem Organizations deploy MFA in ways that create more attack surface than they eliminate. A 2024 MITRE ATT&CK evaluation revealed 68% of enterprise implementations contained at least one critical configuration flaw. The most common: SMS-based MFA without call-back verification, allowing attackers who intercept text messages to

Edgerunner Edgerunner 2 min read

The Security Training Mirage

The Real Problem Security awareness training is an elaborate distraction from the fact that the systems we're asking people to protect are fundamentally designed to fail. We spend hours teaching employees to spot phishing emails, rotate passwords, and report suspicious activity—while the actual attack surfaces have shifted

Edgerunner Edgerunner 2 min read