TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins

TrustSink is a newly disclosed identity attack that turns a trusted MFA step into a password-stealing trap. Rather than sending victims to a clearly fake website, it places a convincing password prompt inside a normal Microsoft Entra sign-in. In the researchers’ test tenant, the victim can complete MFA and reach the intended application without an […]

This article has been indexed from Cyber Security News

Read the original article: