<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mfa on CuraSec</title><link>https://curasec.metacog.co.kr/tags/mfa/</link><description>Recent content in Mfa on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 11:38:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/mfa/index.xml" rel="self" type="application/rss+xml"/><item><title>PowerShell + Graph script to find accounts missing MFA in Entra</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-who-got-missed-in-the-mfa-rollout-x3f-more-powershell-x2b-gr/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-who-got-missed-in-the-mfa-rollout-x3f-more-powershell-x2b-gr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical scripting technique for auditing MFA coverage gaps in Entra ID using Microsoft.Graph.Beta PowerShell; useful reference when validating rollout completeness but no vulnerability or patch action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Password spraying attacks surge 155x as hackers exploit MFA gaps</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-password-spraying-attacks-surge-155x-as-hackers-exploit-mfa/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-password-spraying-attacks-surge-155x-as-hackers-exploit-mfa/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit all login flows for legacy authentication exposure and enforce MFA uniformly — the campaign scale (81M attempts in two weeks) confirms attackers are systematically targeting incomplete MFA coverage and legacy auth protocols. Disable legacy auth (SMTP AUTH, Basic auth, IMAP) in M365/Google Workspace and review Conditional Access or equivalent policies this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Tune SIEM for distributed low-and-slow authentication failures, particularly against legacy protocol endpoints (SMTP, IMAP, RDP, ADFS); run a hunt for accounts with high failed-login volume or successful logins following a spray pattern since the start of H1 2026. Password spraying maps to ATT&amp;amp;CK T1110.003 and is detectable via authentication log anomalies even without specific IOCs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The 155x year-over-year increase from Huntress provides a quantified data point to accelerate legacy auth deprecation and full MFA rollout on the roadmap; use it to justify priority and budget before the next planning cycle, framing the gap in MFA coverage as a measurable risk rather than a configuration detail.&lt;/li>
&lt;/ul></description></item></channel></rss>