DraftKings Warns Users of Credential Stuffing Attacks
DraftKings detected a credential stuffing attack using externally harvested credentials that may have exposed user account data and is enforcing password resets and MFA.
Phishers have found a way to downgrade-not bypass-FIDO MFA
The phishing attack bypasses a multifactor authentication scheme based on FIDO, the standard considered immune to credential phishing attacks, leading to unauthorized access.