Back to all news
Security

Rogue external MFA providers can steal passwords during logins

BleepingComputer·September 22, 2026·1 min read
Rogue external MFA providers can steal passwords during logins

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider, which steals users' passwords during legitimate login attempts. The technique exploits trust in external authentication services, allowing credential theft without triggering suspicion. Organizations should audit MFA provider configurations and restrict privileged access to prevent such attacks, as the method bypasses traditional security controls.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store