Cybersecurity Decrypted #51

Last updated on Sep 18, 2025 1 Minute To Read
Joel Witts Written by Joel Witts

Headlines

Warning As New Attack Targets M365 And Google Workspace With MFA Bypass

VoidProxy is a sophisticated phishing-as-a-service platform that can steal credentials, intercept MFA codes, and hijack sessions in real-time using adversary-in-the-middle (AiTM) tactics. The service lowers the barrier for attackers, enabling widespread phishing campaigns at scale. Only phishing-resistant MFA, like FIDO2 keys, successfully blocked attacks.

Microsoft & Cloudflare “Rugpull” Major Global Phishing Service

Microsoft has disrupted a fast-growing phishing service known as “RaccoonO365”, shutting down over 300 phishing domains. RaccoonO365’s phishing kits are notorious for the low technical know-how required to start sending widespread phishing campaigns to thousands of people. The kits are advertised as being able to avoid spam filters and bypass Multi-Factor Authentication (MFA).

Hackers Want Victims To Install RMM Software—Here’s Why

A new phishing campaign is tricking users with fake browser updates that actually install popular Remote Monitoring and Management (RMM) tools. Once inside, attackers abuse these trusted IT platforms to steal data, maintain persistence, and drop malware —all while blending in with normal network activity.

SonicWall Warns Of Potential Cloud Backup File Breach

SonicWall has disclosed a security incident affecting the MySonicWall cloud backup service, after detecting suspicious activity targeting firewall backup files. Due to the sensitivity of the configuration files impacted, SonicWall is urging customers using the cloud backup service to log into their account and verify if any of their firewalls are flagged as at risk.

From Expert Insights

Podcast: How To Build A Cyber Start Up

In the very first episode of the Women In Cyber podcast, our panel of cybersecurity trailblazers discusses the triumphs, challenges, and lessons learned when building a company. This is a must listen for cybersecurity pros.

ArticleTop 10 Enterprise Cybersecurity Challenges In 2025 

Enterprise cybersecurity is not just about deploying tools; it’s about managing risk at scale and protecting the trust that customers, partners, and stakeholders place in the business. In this article, we take a look at the biggest cybersecurity challenges teams are facing in 2025.

Article: Do You Really Need API Security? A Complete Guide 

API security tools protect data being exchanged between applications. But how real are the risks associated with unsecured APIs, and why aren’t traditional AppSec solutions enough to protect them?

About Expert Insights

Expert Insights helps security and IT professionals make smarter, faster cybersecurity decisions.

Join our community, stay ahead with our podcasts, and get essential insights in our weekly newsletter. Trusted by over one million businesses.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.