Zscaler:网络威胁者利用AI驱动的"文本转网站"工具与实时会话劫持套件,绕过多重身份验证

美股速递
Jun 10

Zscaler Inc. 近期揭示,网络威胁行为体正采用人工智能驱动的“文本转网站”(Text-to-Site)工具与实时会话劫持套件,以规避企业广泛部署的多重身份验证(MFA)防护措施。这些高级攻击技术显著提升了网络钓鱼与凭证窃取活动的复杂性与成功率。

人工智能生成的欺诈性网站能够高度模仿合法登录页面,欺骗用户输入敏感信息。与此同时,实时会话劫持工具可在用户完成MFA验证后立即窃取其活动会话,从而获得对受保护系统的未授权访问权限。这种组合攻击策略使得传统的安全边界与验证机制面临严峻挑战。

网络安全专家指出,此类攻击的演变要求组织超越单一的MFA依赖,转向实施零信任架构、持续行为监控与更强大的端点安全解决方案。随着攻击工具日益智能化与自动化,企业必须采取多层次、自适应的防御策略来应对不断升级的网络威胁。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10