MFA-Minded Attackers Continue to Figure Out Workarounds

Despite the horror stories surrounding multi-factor authentication it’s still a lot better than the simple userid/password combo…:

[…]Earlier this month, for example, security firm Proofpoint reported its disclosure of critical vulnerabilities in Microsoft WS-Trust that could be used to circumvent MFA on cloud services that use the technology — chief among them, Microsoft 365. An attack could have allowed a cybercriminal to use credentials obtained from phishing and credential dumps to log into Office 365, Azure, and other Microsoft services, Proofpoint stated.

Such vulnerabilities are one way of working around the additional security provided by MFA. While security experts underscore that MFA improves the overall security of online users, exploitable vulnerabilities and poor user decisions can undermine those protections.

“When it comes to cloud security, MFA is not a silver bullet,” said Or Safran, senior threat detection analysis at Proofpoint, in an analysis of the vulnerabilities. “As more organizations adopt the technology, more vulnerabilities will be discovered and abused by attackers. However, MFA can improve overall security posture, especially when combined with people-centric threat visibility and adaptive access controls.”

[…]

Original article here