Rogue external MFA providers can steal passwords during logins
Executive Summary
Researchers demonstrated that an attacker with privileged access can register a malicious external MFA provider. When users log in, the rogue provider captures their passwords, enabling credential theft while appearing legitimate.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-22T21:45:45+00:00 - Category: threat-intel
Original Description: Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
"You, yourself, as much as anybody in the entire universe, deserve your love and affection."
— Buddha
Source: Bleeping Computer