Skip to content
Threat Feed

Tag

Mfa

33 briefs RSS
high advisory

eduMFA Token Reusage Vulnerability due to Incorrect InnoDB Snapshot Isolation

eduMFA versions prior to 2.9.1 are vulnerable to token reusage due to incorrect InnoDB snapshot isolation in MySQL and MariaDB versions prior to 11.6.2 (or newer with innodb_snapshot_isolation=off), affecting token types such as TOTP, HOTP, and likely WebAuthN, where tokens are intended for single use, requiring racing the transaction for exploitation.

MariaDB +1 vulnerability mfa token reusage
2r
medium advisory

Azure Entra ID MFA TOTP Brute Force Attempted

Identifies brute force attempts against Azure Entra multi-factor authentication (MFA) Time-based One-Time Password (TOTP) verification codes, characterized by high-frequency failed attempts for a single user across numerous distinct sessions, potentially indicating programmatic attempts to bypass MFA.

Azure Entra ID azure entra_id mfa totp brute_force credential_access
3r 1t
low threat

AWS STS AssumeRole with New MFA Device

This rule identifies when a user has assumed a role using a new MFA device in AWS, which can be indicative of persistence and privilege escalation attempts by threat actors.

exploited AWS Security Token Service +1 aws cloudtrail sts assume_role mfa persistence privilege_escalation lateral_movement
2r 4t
medium advisory

Successful AWS Console Login Without MFA

Successful AWS console logins without multi-factor authentication can indicate compromised credentials, misconfigured security settings, or unauthorized access attempts.

AWS Management Console aws cloudtrail mfa initial-access
2r 1t
high advisory

AWS Virtual MFA Device Registration Attempt

An adversary attempts to register a virtual MFA device to an AWS account, potentially leading to account takeover and unauthorized access to resources.

AWS Identity and Access Management aws persistence mfa account_takeover
2r 1t
high advisory

Okta MFA Disabled by User

Detection of Okta multi-factor authentication (MFA) being disabled by a user account, potentially indicating malicious activity or account compromise and leading to unauthorized access.

Okta Identity Cloud okta mfa account-takeover persistence
2r 1t
medium advisory

Entra ID MFA Disabled for User

Detection of multi-factor authentication (MFA) being disabled for an Entra ID user account, potentially weakening account security and leading to compromise.

Entra ID azure entra_id mfa persistence credential_access defense_evasion
2r 3t
high advisory

Azure PIM Role Activation Without MFA

Detection of Azure Privileged Identity Management (PIM) roles being activated without requiring multi-factor authentication, potentially leading to unauthorized privilege escalation and persistence.

Azure pim mfa privilege-escalation
2r 1t
high advisory

PingID New MFA Method Registered For User

The creation of a new MFA registration in PingID could indicate an attacker attempting to maintain persistence after compromising a user account.

PingID +1 mfa persistence credential-access
2r 3t
high advisory

PingID New MFA Method After Credential Reset

Detection of a new MFA device pairing in PingID shortly after a password reset in Windows Event Logs, potentially indicating a social engineering attack and unauthorized account access.

PingID +2 mfa credential-access
2r 3t
high threat

Okta Multiple Failed MFA Requests Indicate Potential MFA Bypass Attempt

An adversary may attempt to bypass MFA by bombarding a user with repeated authentication requests, potentially leading to unauthorized access and system compromise.

Okta Lapsus$ +6 mfa credential-access mfa-bypass
2r 1t
medium advisory

Okta MFA Reset or Deactivation Attempt

An attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.

Okta Identity Cloud okta mfa credential-access persistence
2r 1t
medium advisory

Okta Authentication Failed During MFA Challenge

Detection of failed authentication attempts during Okta MFA challenges, potentially indicating compromised credentials and attempts to bypass MFA.

Okta Identity Cloud okta mfa authentication account-takeover
2r 3t
medium advisory

Office 365 MFA Notification Email Deletion for Defense Evasion

Attackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.

Office 365 o365 mfa defense_evasion email
2r 1t
high advisory

Office 365 MFA Bypass via Trusted IP Modification

An adversary modifies the trusted IP list in Office 365 to bypass multi-factor authentication (MFA) and gain unauthorized access to accounts.

Office 365 azure o365 mfa bypass defense-evasion
2r 1t
medium advisory

GCP Authentication Failure During MFA Challenge

Detection of failed MFA challenges in Google Cloud Platform (GCP) using Google Workspace login failure events, potentially indicating credential compromise and unauthorized access attempts.

Google Cloud Platform +1 gcp cloud mfa credential-access
2r 2t 1i
high advisory

Azure AD New MFA Method Registered For User

An adversary may register a new MFA method in Azure AD on a compromised account to maintain persistence and bypass existing security controls.

Azure AD azure mfa persistence account-takeover
2r 2t
high advisory

Azure AD Multiple Denied MFA Requests Indicating Potential Account Compromise

Detection of an unusually high number of denied MFA requests for a single user within a short timeframe in Azure AD, potentially indicating a targeted account compromise attempt.

Azure Active Directory azuread mfa account-compromise credential-access
2r 2t
high advisory

Azure AD MFA Fatigue Attack

An attacker attempts to bypass multi-factor authentication by flooding a user with MFA requests, potentially leading to account compromise.

Azure Active Directory mfa azuread credential-access
2r 2t
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
high advisory

Azure AD Authentication Failed During MFA Challenge

Detection of failed authentication attempts against an Azure AD tenant during the MFA challenge, specifically flagged by error code 500121, leveraging Azure AD SignInLogs, which may indicate an adversary attempting to authenticate using compromised credentials on an account with MFA enabled, potentially leading to unauthorized access.

Azure Active Directory azuread mfa credential-access
3r 3t
high advisory

AWS Multi-Factor Authentication Disabled

Detection of AWS Multi-Factor Authentication (MFA) being disabled for an IAM user, indicating potential weakening of account security and persistence attempts.

AWS Identity and Access Management aws cloudtrail mfa iam persistence
2r 3t
medium advisory

AWS IAM MFA Device Deactivation

Detection of AWS IAM MFA device deactivation via the `DeactivateMFADevice` API call, which could indicate an attempt to weaken account protections for privilege escalation or persistence.

AWS Identity and Access Management aws iam mfa deactivation cloudtrail
2r 3t
medium advisory

AWS Console Login Failed During MFA Challenge

Detection of failed AWS console login attempts despite successful MFA usage, indicating potential account compromise attempts.

AWS Management Console +1 aws cloud authentication mfa account-takeover
2r 2t
high advisory

AWS Account Compromise via New MFA Registration

An adversary may register a new Multi-Factor Authentication (MFA) method for an AWS account using the `CreateVirtualMFADevice` event in AWS CloudTrail logs to maintain persistence and evade detection in a compromised AWS account.

AWS +1 cloudtrail mfa persistence
2r 2t
high advisory

AWS MFA Bombing Attack Attempt

An attacker attempts to bypass MFA by flooding a user with authentication requests on the AWS console, as detected through AWS CloudTrail logs showing multiple failed MFA attempts within a short timeframe.

AWS mfa credential-access defense-evasion
2r 2t
high advisory

O365 MFA Disabled by User

Detection of Multi-Factor Authentication (MFA) being disabled for a user account in Office 365, potentially indicating malicious activity or an insider threat.

Office 365 o365 mfa persistence
2r 1t
high advisory

PingID MFA Bombing Attack

Adversaries attempt to bypass multi-factor authentication by flooding users with push notifications, hoping they will eventually accept a fraudulent request, potentially leading to unauthorized access.

PingID mfa credential-access defense-evasion
1r 3t
medium advisory

Google Workspace MFA Enforcement Disabled

Detection of multi-factor authentication (MFA) enforcement being disabled for Google Workspace users, potentially weakening security controls and leading to account compromise.

Google Workspace google-workspace mfa account-compromise
2r 3t
high advisory

GCP Multi-Factor Authentication Disabled

Detection of disabled multi-factor authentication (MFA) for a Google Cloud Platform (GCP) user, potentially leading to unauthorized access and data exfiltration.

Google Cloud Platform +1 cloud gcp mfa persistence defense-evasion
2r 2t
medium advisory

AWS IAM Key Creation with Encryption Policy but Without MFA

Detection of AWS IAM users creating access keys with encryption policies applied while failing to use multi-factor authentication, potentially indicating compromised accounts or malicious privilege escalation.

Identity and Access Management aws iam access_key encryption mfa
2r 2t
high advisory

GCP Multiple Failed MFA Requests Imply MFA Fatigue Attack

Detection of multiple failed multi-factor authentication (MFA) requests for a single user in Google Cloud Platform (GCP) within a short time window, potentially indicating an MFA fatigue attack attempting to bypass MFA and gain unauthorized access.

Google Cloud Platform +1 gcp mfa mfa-fatigue credential-access
2r 3t
high advisory

Azure AD Multi-Factor Authentication Disabled

Detection of attempts to disable multi-factor authentication (MFA) for an Azure AD user by identifying the 'Disable Strong Authentication' operation in Azure Active Directory AuditLogs, which allows adversaries to maintain persistence.

Azure Active Directory azure mfa persistence credential-access
2r 2t