Rogue external MFA providers can steal passwords during logins

BleepingComputer

Overview

Security researchers have discovered a method that allows attackers with privileged access to register a rogue external multi-factor authentication (MFA) provider. This malicious setup can capture users' passwords during legitimate login attempts, posing a significant risk to security. The attack exploits the trust users place in MFA systems, making them vulnerable to credential theft. Organizations that rely on MFA to protect user accounts need to be aware of this tactic, as it undermines the security benefits that MFA is supposed to provide. Users and companies alike must ensure that their MFA providers are legitimate and properly secured to prevent such attacks.

Key Takeaways

  • Affected Systems: Multi-factor authentication systems from various vendors, not specified.
  • Action Required: Organizations should verify the legitimacy of their MFA providers and implement additional security measures to protect against unauthorized registrations.
  • Timeline: Newly disclosed

Original Article Summary

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]

Impact

Multi-factor authentication systems from various vendors, not specified.

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Organizations should verify the legitimacy of their MFA providers and implement additional security measures to protect against unauthorized registrations.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputer

A critical vulnerability in WordPress, identified as CVE-2026-87902, is currently being exploited by hackers. Initially, attackers were probing for sites that were vulnerable, but they have now escalated to exploiting the flaw to write files to disk that can execute shell commands when accessed. This puts numerous WordPress installations at risk, particularly those running outdated or unpatched versions of the software. Users and website administrators need to take this threat seriously, as the exploitation can lead to unauthorized access and control over affected sites. This situation underscores the importance of timely updates and security measures in maintaining website integrity.

Sep 23, 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News

Researchers have identified a serious vulnerability affecting MikroTik routers that allows attackers to gain full administrative control without needing a password or SSH key. Known as the MikroTrick chain, this issue arises from two flaws in the RouterOS software: an SSH state-machine vulnerability (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060). These vulnerabilities can be exploited on routers that are exposed to the internet, putting numerous devices at risk. Users of MikroTik routers should take immediate action to secure their devices, as the potential for unauthorized access could lead to significant data breaches or network disruptions.

Sep 23, 2026

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

darkreading

In the first half of 2026, the United Arab Emirates and Saudi Arabia faced a significant increase in cyberattacks, accounting for half of all incidents reported in the Gulf region. These attacks have become more complex, posing serious challenges for cybersecurity teams in both countries. The rise in incidents affects various sectors, raising concerns about the security of sensitive data and critical infrastructure. This situation highlights the urgent need for enhanced cybersecurity measures and collaboration among nations to combat these evolving threats. The implications of these attacks could be far-reaching, affecting not only businesses but also national security and public trust in digital systems.

Sep 23, 2026

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer

A recent security analysis reveals that a Kubernetes user with limited permissions can exploit a flaw in Google Kubernetes Config Connector to gain control over an entire Google Cloud organization. This issue stems from a confused deputy problem, where the permissions granted to the Config Connector can be misused through a single Kubernetes YAML file. This vulnerability poses a significant risk because it allows unauthorized users to escalate their privileges and potentially compromise sensitive resources across the organization. Organizations using Google Cloud and Kubernetes need to be aware of this risk and take measures to secure their configurations. The implications of such a breach could be severe, affecting data integrity and access control.

Sep 23, 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News

Threat actors have compromised two legitimate MemTensor packages on the npm and PyPI repositories to distribute a malicious program called sckit. This implant targets Windows, Linux, and macOS systems and is designed to steal credentials. Researchers from Aikido, SafeDep, Socket, and StepSecurity have reported on the affected libraries, particularly the @memtensor/memos-cloud-openclaw-plugin versions. This incident raises significant security concerns for developers and users who may have unknowingly installed these compromised packages. It's crucial for affected users to take immediate action to safeguard their systems.

Sep 23, 2026

Arista patches actively exploited VeloCloud Orchestrator zero-day

BleepingComputer

Arista Networks has addressed a zero-day vulnerability in the VeloCloud Orchestrator (VCO) On-Prem deployments, which is currently being exploited by attackers. This flaw poses a significant risk, as it allows unauthorized access to the system, potentially compromising sensitive data and network operations. Users of the VCO should apply the security patches released by Arista immediately to protect their systems. The urgency of this patching process is underscored by the fact that the vulnerability is actively being exploited in the wild. Organizations relying on VeloCloud Orchestrator must prioritize this update to mitigate the risk of an attack and safeguard their network infrastructure.

Sep 23, 2026