Tag: external authentication method
1 article

Rogue MFA Providers Exploit Entra ID for Password Theft
Security researchers have uncovered a sneaky technique called TrustSink that allows rogue MFA providers to swipe plaintext passwords during seemingly normal login attempts, and they've demonstrated it works with Microsoft Entra ID. This alarming exploit lets attackers get their hands on sensitive passwords, complete with timestamps and source IP addresses.