{"id":2808,"date":"2024-03-28T10:03:01","date_gmt":"2024-03-28T15:03:01","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/mfa-bombing-attacks-target-apple-iphone-users"},"modified":"2024-03-28T10:03:01","modified_gmt":"2024-03-28T15:03:01","slug":"suspected-mfa-bombing-attacks-target-apple-iphone-users","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/28\/suspected-mfa-bombing-attacks-target-apple-iphone-users\/","title":{"rendered":"Suspected MFA Bombing Attacks Target Apple iPhone Users"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta1f5eef931ba5a60\/66056bd9975fe7276e523ea2\/password_Arcansel_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers are targeting Apple iPhone users with a rash of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/uber-breach-external-contractor-mfa-bombing-attack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">MFA bombing attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that use a relentless series of legitimate password-reset notification alerts in what appears to be an attempt to take over their iCloud accounts. The activity has focused attention on the evolving nature of so-called multifactor authentication (MFA) bombing attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A report by information security website KrebsOnSecurity first highlighted the campaign, which is targeting business and tech execs. The report quoted multiple individuals who had experienced these incidents recently. A few said they had even <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/dont-answer-phone-inside-real-life-vishing-attack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">received &#8220;vishing&#8221; phone calls<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from individuals purporting to be Apple support staff using a number that spoofed Apple&#8217;s official customer support line.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In conversations with Dark Reading, researchers delved into the activity, highlighting concerning new bombing tactics being used in the campaign.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Password Reset Flood\">Password Reset Flood<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The password reset flood and phone calls appeared to be a highly targeted attempt to trick victims to use their Apple devices to reset their Apple ID. One victim who engaged with the supposed Apple customer support staff reported being startled by the mostly &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/krebsonsecurity.com\/2024\/03\/recent-mfa-bombing-attacks-targeting-apple-users\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">totally accurate<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; information that attackers appeared to have about him as he tried to vet their credibility.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In another instance, an individual reported the push notifications as continuing unabated even after he swapped his old phone for a new iPhone, changed his email address, and created a brand-new iCloud account. Another victim recounted receiving the password reset requests even after enabling a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/support.apple.com\/en-us\/109345\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">recovery key<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for their Apple ID at the request of an Apple support engineer. Apple has touted the key \u2014 an optional feature \u2014 as helping users better secure their accounts and as turning off Apple&#8217;s standard password recovery processes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacker&#8217;s apparent ability to send dozens of reset requests in a short period of time prompted some questions of a potential glitch in Apple&#8217;s password reset mechanism for iCloud accounts, such as a possible &#8220;rate-limit&#8221; problem that incorrectly allows spam-level volumes of reset requests.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Apple did not confirm or deny the reported attacks. Neither did it respond to Dark Reading&#8217;s question on whether the attackers might be leveraging an undisclosed bug in the company&#8217;s password reset feature. Instead, a company spokesman pointed to a support article that Apple published on Feb. 23 offering advice to customers on how to spot and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/support.apple.com\/en-us\/102568\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">avoid phishing messages, phony support calls, and other scams<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The spokesman highlighted sections of the article pertaining to attackers sometimes using fake Caller ID info to spoof phone numbers and often claiming suspicious activity on an account or device to get users to take some unwanted action. &#8220;If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up,&#8221; the advice noted.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"MFA Bombing: An Evolving Cyber Tactic\">MFA Bombing: An Evolving Cyber Tactic<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Multifactor bombing attacks \u2014 also known as multifactor fatigue attacks \u2014 are a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.beyondtrust.com\/resources\/glossary\/mfa-fatigue-attack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">social engineering exploit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in which attackers flood a target&#8217;s phone, computer, or email account with push notifications to approve a login or a password reset. The idea behind these attacks is to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cyberattackers-double-down-bypassing-mfa\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">overwhelm a target<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with so many second-factor authentication requests that they eventually accept one either mistakenly or because they want the notifications to stop.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Typically, these attacks have involved the threat actors first illegally obtaining the username and password to a victim account and then using a bombing or fatigue attack to obtain second-factor authentication to accounts protected by MFA. In 2022, for instance, members of the Lapsus$ threat group obtained the VPN credentials for an individual working for a third-party contractor for Uber. They then used the credentials to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/uber-breach-external-contractor-mfa-bombing-attack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">repeatedly try and log in to the contractor&#8217;s VPN account <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">triggering a two-factor authentication request on the contractor&#8217;s phone each time \u2014 which the contractor ultimately approved. The attackers then used the VPN access to breach multiple Uber systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The twist in the new MFA bombing attacks targeting Apple users is that the attackers don&#8217;t appear to be using \u2014 or even requiring \u2014 any previously obtained username or password.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In previous MFA bombing, the attacker would have compromised the user&#8217;s password either via phishing or data leak and then used it many times until the user confirmed the MFA push notification,&#8221; security researcher Matt Johansen says. &#8220;In this attack, all the hacker has is the user&#8217;s phone number or email address associated with an iCloud account and they&#8217;re taking advantage of the &#8216;forgot password&#8217; flow prompting on the user&#8217;s trusted device to allow the password reset to go through.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The password reset has a CAPTCHA on it to help rate limit the reset requests, Johansen says. But it appears the attackers are easily bypassing that, he notes. The fact that the threat actors are spoofing the legitimate Apple Support phone number and calling the user at the same time as the MFA bombing is another notable difference.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;So, the user is flustered with their device blowing up in MFA requests and they get a call from a legitimate Apple number saying they&#8217;re here to help, just let them know what code they got sent to their phone. I&#8217;m guessing this is a very high success-rate tactic.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Based on available information on the attack, it is likely that the threat actors are going after high net-worth individuals, Johansen adds. &#8220;I suspect the crypto community would be hardest hit, from initial reports,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Jared Smith, distinguished engineer at SecurityScorecard, says it&#8217;s likely the attackers are simply credential stuffing Apple\u2019s reset password forms using known Apple iCloud\/Me.com email addresses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It would be the equivalent of me going to X\/Twitter and plugging your personal email into the reset password form, hoping or knowing you use it for Twitter, and either annoying you or, if I was smart, having some way to get the reset codes from you.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He says it&#8217;s likely that Apple is examining the mass notifications being triggered and considering more stringent rate limiting and distributed denial-of-service (DDoS) protection mechanisms.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Even if the threat actors are using better proxy servers that offer residential IPs, they still seem to be sending such a large volume of attempts that Apple may want to add even more aggressive CAPTCHAs&#8221; or a content delivery network (CDN)-based protection, Smith says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"&quot;Decline by Default&quot;\">&#8220;Decline by Default&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s becoming abundantly clear that stronger authentication beyond MFA is required to secure devices as attackers find new ways to bypass it. For instance, threat actors are currently targeting <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/massive-new-phishing-campaign-targeting-microsoft-email-users\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Microsoft 365<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and Gmail email accounts with phishing campaigns using an MFA-bypass phishing-as-a-service (PhaaS) kit distributed via Telegram called <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/tycoon-malware-kit-bypasses-microsoft-google-mfa\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Tycoon 2FA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that&#8217;s gaining significant traction.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, vishing itself is becoming a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/sophisticated-vishing-campaigns-take-world-by-storm\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">global cybercriminal pandemic<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with highly skilled and organized actors across the world targeting people with knowledge of their personal data. In fact, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.hiya.com\/state-of-the-call.n\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">report published today<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Hiya found that 28% of all unknown calls in 2023 were fraud or spam, with an average loss of $2,300 per user for those who lost money to these attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">MFA bombing and similar attacks &#8220;are a tough reminder that phishers are increasingly finding creative ways to exploit human nature to access people\u2019s valuable accounts, at work and at home,&#8221; notes Anna Pobletts, head of passwordless at 1Password.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">She suggests a &#8220;decline by default&#8221; approach to any phone call or other type of message or alert that &#8220;seems the slightest bit unusual,&#8221; such as an unsolicited call from customer service, even if it seems to come from a trusted entity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Still, this advice isn&#8217;t the optimal solution as it &#8220;puts the burden of security on users,&#8221; Pobletts says. Indeed, the ultimate solution to MFA bypass by attackers may be in using <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/microsoft-adds-passkeys-to-windows-11\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">passkeys,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> which combat phishing attacks like MFA bombing by eliminating the use of credentials, which are &#8220;the reward that hackers are ultimately after,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, until passkeys gain adoption, companies will have to pick up the slack to &#8220;rapidly address vulnerabilities and improve their authentication methods and recovery flows,&#8221; Pobletts adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For iPhone users who want to avoid being targeted by the current spate of MFA bombing, KrebsOnSecurity suggested that they can change the phone number associated with their account to a VoIP number \u2014 such as one from Skype or Google Voice \u2014 to avoid having attackers having access to their iPhone number and thus targeting them. This also will disable iMessage and Facetime on the device, which &#8220;might a bonus for those concerned about reducing the overall attack surface of their Apple devices,&#8221; the site added.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/mfa-bombing-attacks-target-apple-iphone-users\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers are targeting Apple iPhone users with a rash of<\/p>\n","protected":false},"author":12,"featured_media":2809,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2808","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=1000%2C667&ssl=1",1000,667,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=1000%2C667&ssl=1",1000,667,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/suspected-mfa-bombing-attacks-target-apple-iphone-users.jpg?fit=1000%2C667&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2808","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2808"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2808\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2809"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2808"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2808"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2808"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}