New TrustSink attack steals passwords via rogue MFA provider
BreachThe TrustSink attack exploits the trust Microsoft Entra places in configured external MFA providers. An attacker with a compromised privileged Entra account can register a rogue External Authentication Method (EAM).
Read full story at SC Media →