<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mfa-Bypass on CuraSec</title><link>https://curasec.metacog.co.kr/tags/mfa-bypass/</link><description>Recent content in Mfa-Bypass on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/mfa-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>Mirage2FA PhaaS Bypasses M365 MFA, 4,500 US/EU Firms Targeted</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM phishing that defeats standard MFA is a config problem, not a patch problem — audit your Entra ID Conditional Access policies and prioritize migrating M365 users to phishing-resistant MFA (FIDO2/passkeys) this quarter, as TOTP and SMS are insufficient against this class of attack.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> This campaign is active and broadly targeting US enterprises via M365; hunt for AiTM indicators in Entra ID sign-in logs now — flag token issuance from unexpected IPs, session establishment followed by unusual API activity, and impossible-travel events from the same session cookie.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> With 4,500 organizations targeted and ~48% of targeted addresses potentially compromised, confirm with your team this week that phishing-resistant MFA is enforced for M365 and assess whether your domain appeared in ANY.RUN&amp;rsquo;s targeting data; this is board-question territory given the scale.&lt;/li>
&lt;/ul></description></item><item><title>Researchers Demonstrate Three Passkey Attack Classes That Bypass Phishing-Resistance</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-new-passkey-attacks-can-recover-synced-private-keys-or-bypas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you&amp;rsquo;re deploying or have deployed cloud-synced passkeys, evaluate migrating to hardware-bound (device-local) passkeys where possible; the research shows synced passkey material can be exfiltrated by malware and Windows-issued signed auth tokens can be replayed — audit your passkey configuration to prefer non-synced, phishing-resistant authenticators.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> These attacks require malware already present on the endpoint, making detection of credential-theft behaviors (auth token exfiltration, suspicious cloud-sync API calls) the relevant angle — no published IOCs or ATT&amp;amp;CK mappings yet, but worth revisiting passkey-related telemetry if new technique details emerge.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Passkey rollouts sold internally as phishing-proof may need a qualification: device-bound variants maintain that property but cloud-synced ones carry residual risk if endpoints are compromised — useful context for board decks or vendor questionnaire responses that reference passkey adoption.&lt;/li>
&lt;/ul></description></item><item><title>Greatness PhaaS Adds Device Code Phishing to Bypass MFA</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code flow abuse bypasses MFA by design; audit your identity provider (Entra ID, Okta) and restrict or disable the OAuth Device Authorization Grant for users/apps that don&amp;rsquo;t require it — block or conditional-policy-gate this flow this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs provided, but Greatness PhaaS commoditizing device code phishing signals growing campaign volume; build detections in Entra/Okta logs for unexpected device code authorization requests, particularly outside normal device-enrollment windows.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> MFA bypass techniques are now packaged in commercial crimeware toolkits, eroding the assurance value of standard MFA — useful context for risk register updates and for evaluating phishing-resistant auth (FIDO2/passkeys) as a strategic control.&lt;/li>
&lt;/ul></description></item><item><title>Police Dismantle Kratos MFA-Bypass Phishing Kit; Developer Arrested</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-kit-built-to-steal-microsof/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-kit-built-to-steal-microsof/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Kratos used adversary-in-the-middle techniques to steal M365 session tokens and bypass MFA — a reminder that TOTP/push-based MFA is insufficient against phishing; engineers should evaluate phishing-resistant MFA (FIDO2/passkeys) for privileged M365 accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or detection specifics are provided, so no immediate hunt is actionable; the takedown does validate that AiTM session-token theft against M365 was widespread, which reinforces monitoring for anomalous token reuse and impossible-travel sign-ins if not already covered.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The scale of Kratos confirms that MFA bypass via phishing is not theoretical — useful evidence when making the case for phishing-resistant MFA investment or reviewing identity risk with the board; no immediate action required given the infrastructure has been seized.&lt;/li>
&lt;/ul></description></item></channel></rss>