cognitive cybersecurity intelligence

News and Analysis

Search

Researchers Find Way to Bypass Phishing-Resistant MFA in Microsoft Entra ID

Researchers Find Way to Bypass Phishing-Resistant MFA in Microsoft Entra ID

Cybersecurity researchers discovered a method to bypass Microsoft’s MFA by exploiting device code authentication and Primary Refresh Tokens (PRTs). This technique allows attackers to register Windows Hello keys, creating a persistent backdoor. The attack manipulates request parameters to force MFA, complicating detection for users and administrators alike. Prevention demands strict MFA enforcement and vigilant monitoring strategies.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts