ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Varonis Threat Labs developed TrustSink, an attack that lets someone with a highly privileged Microsoft Entra account register a rogue external MFA provider. It shows a fake Microsoft password prompt during legitimate logins, capturing passwords in plaintext while returning a valid token so sign-ins complete normally. Resetting a captured password does not remove the provider, which recaptures the new one.
Tap to vote and see what everyone thinks.
Summary by ByteBrief