Rogue external MFA providers can steal passwords during logins
Security researchers discovered an attack where hackers with privileged access can register rogue external MFA providers to steal passwords during legitimate logins.

Security researchers have developed a novel attack method that allows hackers with privileged access to register rogue external multi-factor authentication (MFA) providers. This security flaw enables attackers to silently steal users' passwords during legitimate login attempts.
According to BleepingComputer, the attack exploits how systems integrate external authentication services. Once attackers gain sufficient administrative privileges, they can insert a malicious external provider that intercepts user credentials before standard verification is completed.
Experts emphasize that this type of threat poses significant risks to enterprise networks and cloud environments. Organizations often rely heavily on MFA as an infallible security layer, frequently overlooking the security posture of third-party authentication integrations.
For IT professionals and businesses in Uzbekistan and the wider region, this discovery serves as a critical security reminder. Conducting thorough audits of all connected third-party authentication providers is just as crucial as securing primary user passwords against modern cyber threats.



