Follow the latest coverage, related explainers and connected technology stories.
Varonis Threat Labs researchers uncovered a technique that allows an attacker who already controls a highly privileged Entra account to register a fake external MFA provider that displays a spoofed password prompt and steals the password during a legitimate sign-in. The attack is not an initial access method, but it may persist after a password change unless the malicious provider is removed from the authentication path.
Attackers are exploiting three vulnerabilities in self-hosted JFrog Artifactory servers to gain administrative privileges, then create persistent accounts and deploy a Rust-written backdoor. A Wiz report warns that between 49% and 62% of internet-accessible Artifactory instances are exposed to at least one vulnerability.