Rogue external MFA providers can reportedly steal passwords during logins
BleepingComputer reports that researchers developed an attack allowing hackers with privileged access to register a rogue authentication provider and steal passwords.
TLDR
BleepingComputer reports that security researchers developed an attack involving a rogue external multifactor authentication (MFA) provider. Hackers with privileged access can register the provider, which steals users’ passwords during legitimate login attempts.
Rogue external MFA providers can reportedly steal passwords during logins
BleepingComputer reports that researchers developed an attack allowing hackers with privileged access to register a rogue authentication provider and steal passwords.
TLDR
BleepingComputer reports that security researchers developed an attack involving a rogue external multifactor authentication (MFA) provider. Hackers with privileged access can register the provider, which steals users’ passwords during legitimate login attempts.