Tech News
← Home  ·  All topics

Mfa

3 GoKawiil briefs on this topic

Varonis details TrustSink attack abusing Microsoft Entra external MFA providers

Varonis Threat Labs disclosed a technique called TrustSink in which an attacker with a highly privileged Entra account registers a rogue external MFA provider that inserts a fake password prompt into legitimate login flows, capturing users' plaintext passwords. The rogue provider still returns a valid signed token to Entra, so the sign-in completes normally with no visible error, and resetting a stolen password does not remove the malicious provider from the authentication flow. Varonis says the method could work with any authentication system using this external MFA model but demonstrated it specifically against Microsoft Entra.

OAuth Consent Grants Emerge as Blind Spot Bypassing MFA in SaaS Attacks

Security researchers warn that attackers can gain lasting access to SaaS and cloud accounts simply by tricking a logged-in user into approving a malicious OAuth application, sidestepping passwords, malware, and multifactor authentication entirely. Once granted, these app permissions can let attackers read email, browse files, pull source code, or touch CI/CD systems through legitimate API access until the tokens or grants are revoked.

Attackers Bypass MFA by Targeting Help Desk Account Recovery Processes

Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.