Rogue MFA providers can quietly recapture changed passwords
Daily Cyber News: Rogue MFA providers can quietly recapture changed passwords
A rogue external authentication provider could steal passwords during apparently normal Microsoft Entra logins. The demonstrated technique requires an attacker to already control a highly privileged account, so this is a post-compromise method rather than a way to gain initial access. Once configured, the malicious provider inserts a convincing password prompt into the legitimate sign-in flow, captures the credential, and then completes the login normally.
Key context: That persistence means password resets alone won’t solve the problem.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Rogue MFA, Rogue, providers, quietly, recapture, changed, passwords.