Episode Details

Back to Episodes

Rogue MFA providers can quietly recapture changed passwords

Season 1 Episode 129 Published 1 week, 2 days ago
Description

Daily Cyber News: Rogue MFA providers can quietly recapture changed passwords

A rogue external authentication provider could steal passwords during apparently normal Microsoft Entra logins. The demonstrated technique requires an attacker to already control a highly privileged account, so this is a post-compromise method rather than a way to gain initial access. Once configured, the malicious provider inserts a convincing password prompt into the legitimate sign-in flow, captures the credential, and then completes the login normally.

Key context: That persistence means password resets alone won’t solve the problem.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, Rogue MFA, Rogue, providers, quietly, recapture, changed, passwords.

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us