Follow the latest coverage, related explainers and connected technology stories.
Varonis Threat Labs researchers uncovered a technique that allows an attacker who already controls a highly privileged Entra account to register a fake external MFA provider that displays a spoofed password prompt and steals the password during a legitimate sign-in. The attack is not an initial access method, but it may persist after a password change unless the malicious provider is removed from the authentication path.