Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Phishing and MFA exploitation: Unlocking the secrets to your digital stronghold

Apr 23, 2026 | Threat Intelligence Research

Attack Trends Targeting Multi-Factor Authentication in 2025

In 2025, attackers adapted their strategies to exploit weaknesses in multi-factor authentication workflows and compromised credentials, according to research insights presented. The study highlights the evolving nature of phishing attacks, which increasingly leveraged the trust associated with initial breaches to launch further attacks within organizations.

Phishing attacks were involved in 40% of security incidents, maintaining their prevalence as initial access vectors. Attackers employed sophisticated cascaded phishing campaigns, using compromised accounts to create tailored lures directed at trusted partners and internal users. The design of phishing emails shifted from traditional spam to workflow-style communications, making them harder to identify as malicious. Keywords commonly used in these phishing attempts included “request,” “invoice,” and “report,” showing a trend towards targeting everyday business tasks which posed familiarity to potential victims. This included the misuse of Microsoft 365 Direct Send, allowing attackers to send internal emails that appeared legitimate, without access to real accounts, thus bypassing scrutiny typically applied to inbound external emails.

The research identified a notable surge in attacks targeting identity and access management applications, with nearly one-third of multi-factor authentication spray attacks focusing on these systems. Attackers exploited weaknesses in authentication workflows to gain access and maintain control over user privileges. Device compromise incidents saw a distressing increase of 178%, largely driven by voice phishing techniques aimed at tricking administrators into accepting malicious devices. In particular, the higher education sector emerged as a significant target due to its diverse device ecosystem, coupled with potentially lax security protocols.

Defensive Context

Organizations utilizing multi-factor authentication must remain vigilant against tailored phishing attacks that exploit initial compromises. Higher education and sectors with diverse and unmanaged devices need to particularly focus on strengthening their identity and access controls. The study underscores the necessity of ensuring robust scrutiny for internal communications and adherence to strict device management policies.

Why This Matters

The shift towards cascaded phishing attacks and increased targeting of identity systems presents real-world risks for organizations, especially those in sectors like education where lax security protocols may exist. Companies with low scrutiny for internal communications could be more exposed to these sophisticated phishing techniques.

Defender Considerations

Organizations should prioritize monitoring for signs of phishing-related activities, especially for lures that appear to originate internally. Implementing stricter verification for direct send protocols and being cautious of managed devices could help reduce risks associated with compromised internal communications. While broad security measures are fundamental, tailoring defenses to specific environments and sectors is essential for effective threat mitigation.

The study highlights an important focus on evolving phishing tactics and their significant implications for organizational cybersecurity frameworks, demanding ongoing adaptation and vigilance.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles