Skip to main content

Tag: trustsink

1 article

Laptop screen shows login page with blurred university background and person working in foreground.

Rogue MFA Providers Exploit Entra ID for Password Theft

Security researchers have uncovered a sneaky technique called TrustSink that allows rogue MFA providers to swipe plaintext passwords during seemingly normal login attempts, and they've demonstrated it works with Microsoft Entra ID. This alarming exploit lets attackers get their hands on sensitive passwords, complete with timestamps and source IP addresses.

Analyst 207