Streamlinefeed.Co.Ke Cybersecurity COO Disables MFA, Exposing Firm to Attacks
Article Content
- •A COO disabled MFA, exposing the firm to significant security risks.
- •The issue originated from a faulty third-party invoicing application.
- •Over 1.2 billion cyber threats were reported in Kenya in early 2026.
A COO at a cybersecurity firm ordered the disabling of multi-factor authentication (MFA) after a minor software glitch affected a few mobile devices. This decision, made without waiting for a technical workaround, left the company vulnerable to credential stuffing and phishing attacks. The IT team had previously implemented MFA to improve the firm's Microsoft Secure Score, but the COO's actions undermined this effort. The issue was traced to a third-party invoicing application that falsely claimed MFA compatibility. Despite identifying the root cause, the COO insisted on an immediate rollback of security protocols. This incident reflects a broader trend of executives bypassing security measures when faced with operational challenges. In Kenya, similar resistance to security protocols is prevalent, with over 1.2 billion cyber threats reported in early 2026. The Central Bank of Kenya has mandated robust MFA in response to rising ransomware attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…