Connect with us

Tech & AI

Rogue external MFA providers can steal passwords during logins

Published

on

Authentication

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users’ passwords during legitimate login attempts.

The technique, dubbed TrustSink by Varonis Threat Labs, can work with any provider that relies on this external authentication model, though the researchers demonstrated the attack using Microsoft Entra.

Microsoft Entra supports external MFA providers, which allow organizations to use third-party authentication services to satisfy multifactor authentication requests.

According to Microsoft, when a user signs in with a first factor, such as a password, Entra can redirect them to an external MFA provider to complete the required second factor.

Advertisement

If the provider returns a valid signed token indicating that the second factor was completed, Entra considers the MFA requirement satisfied.

Varonis found that an attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) as one of these external MFA providers and use it to insert a convincing Microsoft password prompt into the legitimate authentication flow.

The fake prompt captures the user’s password in plaintext before the malicious provider returns a valid signed token to Entra, causing the login to complete without displaying an error.

“In our test tenant, every sign-in completed normally while our server received passwords with timestamps and source IP addresses,” explains Varonis.

Advertisement

“Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user’s next sign-in.”

It is important to note that TrustSink is not an initial-access attack and requires an attacker to already control a highly privileged Entra account.

Abusing an external MFA provider

TrustSink abuses the trust Microsoft places in a configured external MFA provider.

Varonis created a malicious provider that appeared to Entra as a legitimate external MFA provider but displayed a copy of Microsoft’s password page to the user.

Advertisement
The TrustSink attack
The TrustSink attack

During the proof-of-concept attack, the login initially proceeds normally, with the user entering their email address and password on Microsoft’s legitimate login.microsoftonline.com site.

When MFA is triggered, Entra redirects the browser to the attacker’s external MFA provider for the second authentication step.

Instead of presenting a legitimate second-factor challenge, the malicious provider displays a copy of Microsoft’s password prompt.

External MFA provider showing a Microsoft login prompt
External MFA provider showing a Microsoft login prompt
Source: Varonis

If the victim enters their password again, believing Microsoft is requesting it as part of the authentication process, the credential is sent to the attacker-controlled server.

The rogue provider then generates a signed token stating the MFA prompt was completed and returns it to Entra, allowing the user to continue to the application they originally attempted to access.

From the victim’s perspective, the sign-in appears to have completed normally.

Advertisement

Varonis says the attack is convincing because the fake password prompt appears when the user already expects another authentication step.

The researchers say the page uses the same fonts, layout, and button design as Microsoft’s legitimate login page and appears immediately after the victim enters their real password on Microsoft’s domain.

Varonis says TrustSink builds on previous research by security researcher Dirk-Jan Mollema, presented at x33fcon 2025 in a talk titled “Bringing Your Own Identity in Entra ID.”

Mollema showed how a rogue registered external MFA provider could satisfy an MFA requirement by returning a signed JWT claiming authentication had succeeded without actually performing the expected authentication check.

Advertisement

TrustSink abuses the same attack for credential theft.

Varonis says registering the malicious external method requires modifying the Authentication Methods Policy and creating an application, service principal, and consent grant.

Those actions require a Global Administrator or Authentication Policy Administrator account, making TrustSink a post-compromise technique.

Once installed, however, the rogue provider can remain in the authentication path for targeted users across subsequent logins.

Advertisement

Because the rogue MFA provider remains registered in the tenant’s Authentication Methods Policy, even if a user changes their password, it will be recaptured on the next log in attempt.

Varonis therefore warns administrators to remove the malicious provider before rotating affected credentials.

Varonis recommends removing suspicious external MFA providers and their associated applications, keys, and redirect URIs before resetting affected users’ passwords.

Organizations should also monitor changes to the Authentication Methods Policy, limit standing Global Administrator and Authentication Policy Administrator privileges, and use phishing-resistant authentication methods such as FIDO2 or Windows Hello for Business.

Advertisement

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech & AI

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming

Published

on

But a Chromium-based design means it can only be so efficient.

Discord is working on a new mode for its social platform that it says might be less resource-intensive. Screenshots of an option called Game Mode began circulating on social media over the weekend. The description shown for the Game Mode toggle states that it will “Reduce Discord’s CPU and GPU usage while a game is running.” By making the chat platform less resource-intensive, concurrently running software should be able to run more smoothly.

Today, the company confirmed on X that this experimental mode will begin rolling out to its users next week. The brief official announcement about Game Mode added that Discord is “aiming to add more resource-saving features over time.”

Discord is based on the Electron web app framework, which uses Javascript and Chromium for creating software. The open-source Chromium, which is the basis for Google’s Chrome and several other browsers, is not known as the most efficient tool for web development. A feature like Game Mode could offer some performance improvements, especially while also running a beefy AAA game on the same machine, but there may only be so far that Discord will be able to streamline on its current architecture.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Meta-Led Anti-Terrorism Group Faces Mass Resignation of Expert Advisers

Published

on

Six of the nine independent experts on the advisory board of the Global Internet Forum to Counter Terrorism—a consortium run by several of the biggest US tech companies—resigned on Monday, according to a letter seen by WIRED and interviews with three of the people.

The tensions between the independent advisory committee and the GIFCT date back to an email the counterterrorism and free speech experts received in July from Meta’s Nell McCarthy, a vice president overseeing content policy. For years, the group had advised the GIFCT on how to prevent platforms from becoming havens for the radical organizations and individuals blamed for some of the world’s worst mass violence.

But McCarthy wrote that while the consortium welcomed the experts’ insights on violent trends, it no longer desired their scrutiny on the effectiveness of Big Tech’s efforts to curtail violence. Meta and other leaders wanted to “refresh” the 6-year-old independent advisory committee the experts sat on, she wrote. Meta currently serves as chair of GIFCT’s operating board, giving it outsized influence over policy changes, though other companies on the panel must ultimately approve.

New additions to the rotating advisory committee had previously been elected by current members; under the plan laid out in July, they would instead be picked by tech companies. The committee would be barred from weighing in on key topics such as the consortium’s performance and making recommendations together as a group. Its role as a watchdog would be neutered, advisers believed.

Advertisement

In their resignation letter, the departing members of the committee wrote that their appeals against the plan had been “ignored” and that, in turn, they had “lost confidence in the GIFCT’s ability to deliver effectively on its founding mission” to prevent terrorists from exploiting online services. “We all know that a body that cannot scrutinise, take a position, or evaluate is not an advisory body at all,” the letter stated. “It is decoration and accountability theatre.”

Meta deferred comment on the resignations to the GIFCT. An unsigned statement sent to WIRED by a GIFCT spokesperson on behalf of the consortium’s leadership and the Meta-chaired operating board says the proposed changes have been “informed by several rounds of feedback” and are not yet final. They came out of discussions on “how to more effectively engage civil society and governments for substantive input” as “multi-stakeholderism is a core principle” for the GIFCT.

The consortium has about 35 members; other long-time board members include Microsoft and YouTube. A small staff alerts members to violent content, helps them exchange threat intelligence, and commissions research on countering extremism. While the coordination has helped some platforms combat problematic content, critics believe the group isn’t living up to its potential.

A WIRED investigation in 2024 uncovered several issues with GIFCT, including Meta delaying TikTok’s membership bid and poor relations between the companies at the helm and the unpaid independent advisory body. It also revealed failures in the tip-sharing database the consortium oversees to coordinate takedowns of problematic content.

Advertisement

The dismantling of the advisory group threatens to deteriorate the organization’s work further at a time when balancing free expression and online safety has become more challenging. Generative AI tools have simplified content creation but imposed limited guardrails.

Extremist content, including some that is now AI-generated, that promotes organizations such as Islamic State remains a persistent issue. Newer nihilistic collectives have turned to AI-supported scams such as sexploitation to coerce young victims into carrying out violence and abuse. Several AI chatbots have been accused of facilitating violence.

“A Shame”

The experts who resigned include university researchers and representatives of civil society organizations. They had agreed with McCarthy on the need for changes to improve the results of the decade-old anti-terrorism consortium. But they believe the proposal, which could be finalized soon, amounts to a step backward.

“There won’t be critical voices raising concerns about what GIFCT is doing or is not doing,” one of the departing experts says. “It may seem politically convenient for them to abolish the independent advisory committee, but they are going to regret it in the longer term.”

Advertisement

Source link

Continue Reading

Tech & AI

SpaceX’s Latest Starship Mission Reached Low-Earth Orbit

Published

on

The successful mission also deployed 26 of SpaceX’s latest Starlink satellites.

For its 14th flight, SpaceX’s Starship powered by its Super Heavy megarocket has entered low-Earth orbit for the first time. SpaceX kicked off this major undertaking early Monday morning but had to deal with some hiccups on the way, including losing one of its six Raptor engines. Ultimately, SpaceX decided to push on with the mission and successfully reached orbit albeit with some compromise.

SpaceX originally planned to have Starship orbit Earth six times over a span of nearly 10 hours for the Flight 14 mission. With one of the engines offline, the plan changed to only spend approximately three hours in orbit before reentering the Earth’s atmosphere and landing in the Pacific Ocean. As part of the same mission, SpaceX managed to deploy 26 of its Starlink V3 satellites into orbit. SpaceX said that its Starlink team has made contact with all newly-deployed 26 satellites in orbit, which will eventually be used to improve Internet speeds for customers. While previous Starship missions also carried several V3 satellites, they only remained in suborbital space and served as test flights to see if the new satellites would connect to the existing Starlink constellation.

While Starship’s flight 14 marked a major milestone of reaching orbit, the mission also served as a test of the reusability of its Super Heavy rocket. After providing the necessary boost to Starship, Super Heavy landed in the Gulf of Mexico, where it will eventually be retrieved, but not by a launch tower‘s “chopsticks” as previously demonstrated.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Jet Megatextures Demo For ESP32-S3

Published

on

Mipmapping is a good way to add a lot more detail to a 3D scene without overburdening the rendering hardware with detail that won’t be seen by the user. This level-of-detail rendering technique was demonstrated on the N64 console hardware a few years ago by [James Lambert] with [Michael Biggins], also known as [PhonicUK], now demonstrating it on the ESP32-S3 using his own Jet rendering engine.

Although level-of-detail rendering really speeds things up, it does also require far larger texture sizes, with [James]’s N64 demo taking up 40 MB of a 64 MB cartridge. To fit it on an ESP32-S3 with 16 MB of PSRAM and no SD card expansion or such the textures were further compressed to use 8-bit indexing, resulting in a mere 5.01 MB of textures.

There’s a demonstration video over on the associated Reddit thread, which shows the camera moving through the scene. Even if not as exciting as the Wipeout port by [Michael] that we previously covered, it does make clear that even without a proper 3D GPU the ESP32-S3 is already a pretty capable gaming machine that can go toe-to-toe with some 1990s consoles.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

These Extremists Are Running for Election in November

Published

on

There are five weeks left until the midterm elections, and extremism is on the ballot in much of the US. A WIRED review of candidates running for statewide and federal positions in November, along with exclusive data on candidates running for state-level positions, reveals hundreds of Republican candidates who openly express virulently hateful ideologies, share racist content online, have close ties to white supremacist and antisemitic figures, and are members of far-right groups online. President Donald Trump and his administration have openly embraced, endorsed and defended many of these candidates.

At a local level, over 500 candidates running for state legislator positions in November are members of far-right groups on Facebook that promote militias, gun rights, and Christian nationalism, according to data collected by the Institute for Research and Education on Human Rights and shared with WIRED.

While many extremist candidates—such as groyper James Fishback and antisemitic influencer Dan Bilzerian— didn’t make it through GOP primaries, many made it to the general election, and a number of them are expected to win.

“The candidates are taking a page out of the Trump administration’s playbook,” Luke Baumgartner, a former research fellow at George Washington University’s Program on Extremism, tells WIRED. Baumgartner claims that many of the candidates running in November have been inspired by those in the White House. “In essence, the executive branch has handed them a permission slip to say and do what would have been unthinkable during the George W. Bush, McCain, or [Mitt] Romney eras of the GOP,” he says.

Advertisement

Extremist rhetoric has led to real world political threats. In 2025, terrorism and targeted violence incidents rose 19 percent compared to 2024, according to researchers at the University of Maryland; the US Capitol Police reported an increase in “threat assessment cases” against members of Congress for the third year in a row, with a 58 percent increase from 2024; and the US Marshals Service documented threats against almost 400 judges, a roughly 5 percent increase from the previous year.

Here are five races involving candidates who have shared extremist ideologies or have close ties to extremist figures, that WIRED is watching ahead of the November midterms.

The Texas Railroad Commissioner Race

MANSFIELD TEXAS  APRIL 15 Tarrant County Republican Party Chair Bo French speaks during a rally on Tuesday April 15 2025...

Photo-Illustration: WIRED Staff; Getty Images

Bo French, the GOP candidate for Texas Railroad Commissioner, is so extreme that Republican strategist Karl Rove has said he would vote for a Democrat rather than supporting a “bigot.”

Source link

Advertisement
Continue Reading

Tech & AI

Detachable mop heads and top-tier cleaning make the affordable Roborock Qrevo 2 Pro a dream for mixed floors

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

Roborock Qvero 2 Pro: 30-second review

The Qrevo 2 Pro is the latest robot vacuum and mop combo cleaner from Roborock and includes detachable mop plates to help ensure it doesn’t get carpets wet while cleaning.

Cleaning performance is a match for some of the most expensive options on the market with its mopping being as good as I have ever tested making it a fantastic pick for the price.

Advertisement

Source link

Continue Reading

Tech & AI

New StandBy faces revealed for iPhone Duo

Published

on

The forthcoming iPhone Duo has more features than Apple has revealed, including a whole series of faces for its StandBy mode. Here’s what to eventually look for.

While pre-orders for iPhone Duo don’t start until October 16, and the Xcode betas still don’t show developers everything, one has found many new options coming to iOS 27 for this device.

Developer pdfu reports that the Xcode 27.1 simulator is lacking Rushmore, an app that is for displaying the new StandBy faces. But despite that, they have managed to get certain of the new faces running.

These working ones are variants on familiar clock and calendar faces as used on the iPhone‘s current StandBy mode. But code references describe several more options.

Just because something is referenced in code, it doesn’t necessarily mean that it will launch immediately. But those code references show five more faces:

  • Home Camera: up to nine camera views
  • Home Module
  • Flow
  • Fade
  • Snoopy

There are no details for Home Modular, Flow, or Fade. But the code for Flow also includes the term ResponsiveArt, which suggests that it will at least be an animated face.

Face editor

The iPhone Duo will also feature a revised editor for customizing these StandBy faces. It’s very similar to the existing one on iPhone and is perhaps more like the Apple Watch face editor.

Advertisement

Users can swipe left and right to adjust, for instance, the style of an analog clock, its numerals, light mode and dark mode, plus the color of the face and the hands.

Some of these clock faces also have room for two widgets. Then some more are digital instead of analog and there pdfu has found code references for five layouts:

  • StandBy
  • Stacked
  • Top
  • Middle
  • Bottom

The presumption is that all but the StandBy one may actually be intended for when the iPhone is opened like a book.

Developer pdfu has a strong track record for examining beta code. They confirmed that the iPhone Duo would use Touch ID, for instance, and most recently uncovered that Siri could be replaced by Claude or ChatGPT.

Advertisement

Source link

Continue Reading

Tech & AI

JadePuffer agentic AI attacks target Azure, destroy cloud resources

Published

on

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.

The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption.

Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.

Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts.

Advertisement

The destructive stage lasted seven minutes and targeted more than 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services.

Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections.

Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals – security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources.

Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other “performed discovery, destructive operations, and credential collection.”

Advertisement
Timeline of observed attacks
Timeline of observed attacks
Source: Microsoft

The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an effort to make restoration more difficult.

This operational pattern could further support ransomware extortion, although Microsoft did not report anything about financial demands and didn’t confirm data theft in the observed cases.

According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed.

“The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type,” Microsoft said.

Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded.

Advertisement

Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks.

The researchers recommend several mitigation steps and guidance for system administrators, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Advertisement
Continue Reading

Tech & AI

Xiaomi And Motorola Launched Phones At Snapdragon Summit. Here’s Why I’m Excited For Each One

Published

on





Snapdragon Summit in Maui, Hawaii, has come and during the show, Qualcomm (who paid for my travel and accommodations) announced two new top tier phone processors. They are the Snapdragon 8 Elite Gen 6 and the Snapdragon 8 Elite Extreme Gen 6. The former is the successor to last year’s flagship while the latter is a new even more premium tier of performance.

Both chips run off of two 5GHz prime cores and six 4GHz performance cores built on a 2nm process. The key differences between the two include Matrix cores included in the Extreme’s GPU, additional video processing (8K/60fps) on the Extreme, and more. For the average consumer, you probably won’t notice a ton of differences between the two in day-to-day tasks, but when it comes to gaming, AI (agentic AI was a key theme at the conference), and sustained performance, that’s when you’ll notice the difference.

According to Qualcomm, the reason for the two premium tiers stems from phone maker demand. Consumers have been vying for more premium options in the smartphone space, and these chips are designed to address that need. Speaking of phones, there were two major phone announcements at Snapdragon Summit. The Xiaomi 18 Pro and Pro Max will run the Elite and Extreme processors respectively. The Motorola Signature 27 will also run the Extreme chip, and both of those phones are exciting for different reasons.

Advertisement

Motorola Signature 27 brings Motorola back into flagship territory

Motorola’s Signature series of smartphones have typically been reserved for overseas sales only, with no presence in the U.S. That looks to change with the Signature 27, which will get a North American release. The Signature 27 is peak Motorola flagship material — Snapdragon 8 Elite Extreme Gen 6, a six-antenna design, a 200-megapixel telephoto lens, and Bang & Olufsen audio, which was recently announced.

Those specs all sound great, but it’s mostly just great to see a Motorola flagship on U.S. shores again. Motorola has been doing very well with its flip phones and midrange candybar phones, but it’s been a while since a real flagship came to the States, so that alone is worth celebrating. That’s especially true in light of OnePlus’s exit from the U.S. market — there’s another premium flagship taking its place, and it looks like a real beast. Stay tuned to SlashGear for more news about the Motorola Signature coming — hopefully — soon.

Advertisement

Xiaomi 18 Pro and 18 Pro Max split the difference

Xiaomi is a phone that will not come to the U.S., though it will likely be relatively easy to import if you so choose. The 18 Pro series brings a boatload of great specifications to the table, and it also represents the diversity that Qualcomm was talking about. Both phones have similar specifications and capabilities, and they also bring a couple of neat features to the lineup as well.

The first is the rear-facing screen. Picture an iPhone 18 Pro, and replace the camera island with a rear facing screen. You can use this for taking selfies with the main cameras, but Xiaomi will also bring some apps and functionality to the rear screen as well. The options we could play with were limited to things like answering calls, playing music, and some AI-generated animals, which were admittedly pretty cute, but not terribly functional.

Advertisement

The other cool thing, and honestly the thing that excites me the most, is the privacy display. This works basically the same as the Samsung Galaxy S26 Ultra’s display with pixels that turn off, and software that runs the whole thing. Xiaomi re-did the subpixels a bit, which is supposed to give better color even with the privacy display on, and it was not terribly noticeable, but it’ll take more experimentation to determine. But I mainly like the idea that someone else beyond Samsung is making this feature. Hopefully it’s only a matter of time before it catches on with more phone makers.



Advertisement

Source link

Continue Reading

Tech & AI

Who Makes Thor Appliances And Where Are They Manufactured?

Published

on





Though perhaps too much of a newcomer to make our ranked list of every major refrigerator brand, Thor has established itself as a manufacturer of high quality, professional-grade fridges and other appliances at a significantly lower price point than other premium brands.

Thor makes and sells its appliances under the Thor Kitchen brand based out of Southern California. It’s a privately held, independent company that produces a wide range of kitchen equipment appliances, from gas and electric ranges to dishwashers, outdoor kitchen gear, and even wine coolers. While its products are designed in the U.S., they appear to largely be manufactured in China, often with components from other international sources.

Advertisement

The company’s corporate headquarters is in the greater Los Angeles area, technically in Montclair but near Ontario and a smidge northeast of Anaheim, where some reporting has placed it. It emphasizes high-end design that resembles the aesthetic and functionality of professional kitchens (its fridges, for instance, do some of the things luxury fridges are capable of that conventional models lack like specialized wine storage) with lots of stainless steel and a focus on seamless integration.

Advertisement

Thor appliances are manufactured in China

Though the company’s corporate structure largely lives in the United States, unlike these refrigerator brands that build their models in America, Thor’s appliances are manufactured and assembled in China. According to an authorized Thor dealer, its ranges are built in China, though they’re constructed with European and American components. Shenzhen Qiaoyi Industrial and Guangdong Hyxion Smart Kitchen, major Chinese manufacturers that specialize in residential appliances and outdoor kitchens, are major suppliers for Thor Kitchen.

Though final assembly may happen in China, like so many major appliance manufacturers, Thor relies on a global supply chain. Gas valves may be sourced in Spain and burners from Italy, while igniters arrive from the U.S. However, it’s important to note that this info is drawn largely from a dealer’s description, meaning that not every component in every Thor model comes from the countries listed. Suppliers and components may vary based on both the specific model and even across different production runs.

Advertisement



Source link

Continue Reading

Trending

Copyright © 2025