chiprook
← Security
SecuritySeptember 23, 2026, 04:45

TrustSink: rogue external MFA provider steals passwords in Microsoft Entra logins

Varonis Threat Labs detailed TrustSink, an attack where an adversary with privileged access registers a rogue external MFA provider in Microsoft Entra that shows a copy of Microsoft's password prompt, captures the password in plaintext, then returns a valid signed token so the login completes normally.

TrustSink: rogue external MFA provider steals passwords in Microsoft Entra logins
#Microsoft#Entra#Varonis
Read next
Security

Bitdefender launches a VPN built for AI agents, not people

Security

Over 80,000 Relay Servers Mask Chinese Access to Frontier AI Models

Security

Estonia's CybExer to Lead Security Testing for IRIS² Satellite System

Security

Chinese hackers hit 996 Zyxel switches and WordPress sites