Varonis Threat Labs disclosed a technique called TrustSink in which an attacker with a highly privileged Entra account registers a rogue external MFA provider that inserts a fake password prompt into legitimate login flows, capturing users' plaintext passwords. The rogue provider still returns a valid signed token to Entra, so the sign-in completes normally with no visible error, and resetting a stolen password does not remove the malicious provider from the authentication flow. Varonis says the method could work with any authentication system using this external MFA model but demonstrated it specifically against Microsoft Entra.
bleepingcomputer.com
· 2026-09-22
Security researchers warn that attackers can gain lasting access to SaaS and cloud accounts simply by tricking a logged-in user into approving a malicious OAuth application, sidestepping passwords, malware, and multifactor authentication entirely. Once granted, these app permissions can let attackers read email, browse files, pull source code, or touch CI/CD systems through legitimate API access until the tokens or grants are revoked.
darkreading.com
· 2026-09-18
Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.
bleepingcomputer.com
· 2026-09-09