05/30/2026
As part of our efforts to keep our clients informed on relevant cybersecurity topics, More Power Technology Group wanted to share the two resources below. These were recently reviewed by Andrew Harsha (MPTG Security Analyst), who recommends taking a moment to review them and consider sharing them with staff.
The more informed we are, the better we can prevent potential risks and strengthen our overall preparedness.
Kali365 Phishing Kit Enabling Full MFA Bypass
Link: https://www.ic3.gov/PSA/2026/PSA260521
This advisory warns of an active and widespread Microsoft 365 account takeover technique that completely bypasses MFA by tricking employees into authorizing an attacker's device through a fake verification code, with no password required and no MFA prompt triggered.
Silent Ransom Group Targeting of US Legal, Insurance, and Healthcare Sectors
Link:https://www.ic3.gov/CSA/2026/260526.pdf
This advisory warns of the Silent Ransom Group (SRG/Luna Moth), who cold-call employees impersonating IT support, convincing them into granting remote desktop access, and in some cases send someone physically to your office to plug in a USB drive and steal data directly. They then extort victims by threatening to publish stolen data publicly. No system or encryption techniques are used, as this group exclusively focuses on rapid data theft and extortion.
If you or your staff have any questions regarding these threats or how we can work together to mitigate them, please call or email us for additional information. Thank you!