Find notable cyber news and cases, enriched with sources, timelines, and signals.

TrustSink rogue external MFA provider attack against Microsoft Entra

Technical Analysis
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creating credential-theft risk for organizations that rely on external authentication. The attack can keep working across password resets until the rogue provider and related tenant objects are removed.

Related Happenings

Windows 11 KB5124008 Active Directory domain trust breakage

Service Disruption
H score0 First: 16.09.2026 23:39 Last: 16.09.2026 23:39 Sources 1

About this happening: The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microso...

Latest development: 17.09.2026 11:24

Microsoft shared a temporary workaround for Windows 11 systems where the September 2026 security updates trigger Machine Identity Isolation enforcement and break domain trust and valid credential sign-ins on enterprise devices. Admins should disable Machine Identity Isolation using the same method used to enable it, restart the device, and reset the secure channel; Microsoft also says the feature is only supported in environments connected to Windows Server 2025 Domain Functional Level (DFL) and above.

Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)

Vulnerability
H score49 First: 21.08.2026 09:06 Last: 21.08.2026 09:06 Sources 1

About this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
H score31 First: 10.08.2026 15:25 Last: 10.08.2026 15:25 Sources 1

About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Timeline

  1. 23.09.2026 00:45 2 articles · 0h ago

    TrustSink steals passwords through rogue Microsoft Entra MFA providers

    Initial Disclosure

    Varonis Threat Labs described TrustSink, a post-compromise technique in Microsoft Entra where an attacker with already privileged access can register a rogue External Authentication Method, inject a fake Microsoft password prompt during legitimate sign-in, and capture passwords in plaintext before returning a valid signed token to complete the login. The guidance also warns administrators to remove suspicious external MFA providers and related applications, keys, and redirect URIs, then reset affected credentials after the malicious provider is gone.

    Show sources