09/29/2026, 19.27
TrustSink: The Rogue MFA Attack Targeting Microsoft Entra
Varonis Threat Labs reveals TrustSink, a post-compromise technique using rogue external MFA providers to steal plaintext passwords during legitimate logins.

Key points
- TrustSink abuses Microsoft Entra's external MFA provider feature to capture plaintext passwords.
- Attackers must already possess high-level privileges, such as Global Administrator access.
The rest of this article is for registered readers
Your email is enough: we send you a six-digit code, no password.
Sign in and keep readingNo password, no cost.Hai una domanda su questo dossier?
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email
See also
Nvidia Eyes Insurance Partnerships to Scale AI Infrastructure
Nvidia is in early talks with insurers to mitigate financing risks for neocloud providers, aiming to turn AI chips into a standardized investable asse…
29/09/2026 19:41
L'Oréal and OpenAI Partnership: Redefining Beauty via Agentic Commerce
L'Oréal partners with OpenAI to integrate AI-native shopping, virtual try-ons in ChatGPT, and advanced microbiome research to dominate the global beau…
29/09/2026 19:41
Apple, IBM and AI Tools: Critical Vulnerabilities Hit Global Tech
New security alerts reveal critical flaws in Apple OS, IBM Guardium, and FlowiseAI, highlighting a surge in active exploitation and data exposure risk…
29/09/2026 19:41
Anthropic IPO Filing: Massive Growth Meets Existential Risk Warnings
Anthropic's S-1 filing reveals a trillion valuation target, .6 billion in revenue, and stark warnings that its AI could pose existential risks to…
29/09/2026 19:40
CyberShield AI Italia: Rome Convenes National Digital Defense Summit
Italy launches CyberShield AI to protect strategic infrastructure. A high-level summit in Rome unites government, NATO, and tech leaders on AI cyberse…
29/09/2026 19:40









