[SECURITY]■ STORY TIMELINE
ROGUE MFA PROVIDERS CAN STEAL PASSWORDS
Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.
Bleeping Computer+0m
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider…