A tool called Modlishka, the English pronunciation for the Polish word for “mantis,” is the latest in a list of ways to bypass two-factor authentication (2FA) State actors have found a way to fool targets into giving away their Gmail and Yahoo! 2-step verification codes. The tool sits between the legitimate website it is impersonating and the phishing website the user is seeing. Users should use 2FA hardware tokens, such as Yubikey, RSA SecurID and the Titan ID that support the Universal 2nd Factor standard.”]

