security1 publisher
A rogue external MFA provider plants a fake Microsoft password prompt in Entra's login flow
Varonis Threat Labs' TrustSink needs an already-compromised Global Administrator or Authentication Policy Administrator account. Once the method is registered in the Authentication Methods Policy, it keeps capturing passwords through resets.
Publishers:bleepingcomputer.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+14
- Incentives68
- Confidence57