THEMETASEC

Cybersecurity News, Aggregated

New TrustSink attack steals passwords via rogue MFA provider

SC Media · 1 hour ago Breach

The TrustSink attack exploits the trust Microsoft Entra places in configured external MFA providers. An attacker with a compromised privileged Entra account can register a rogue External Authentication Method (EAM).

Read full story at SC Media →