Close Menu
OnlyPlanz –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Can Buzzy Marketing Bring Back JCPenney? CMO Marisa Thalberg Is Betting on It

    December 16, 2025

    Employment Rights Bill clears last parliamentary hurdle

    December 16, 2025

    Donald Trump sues BBC for up to $10bn over edit of January 6 speech | Donald Trump

    December 16, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Can Buzzy Marketing Bring Back JCPenney? CMO Marisa Thalberg Is Betting on It
    • Employment Rights Bill clears last parliamentary hurdle
    • Donald Trump sues BBC for up to $10bn over edit of January 6 speech | Donald Trump
    • Godox launches updated and improved AD300 Pro II all-in-one outdoor flash
    • US lost 105,000 jobs in October and added 64,000 in November, according to delayed data | US economy
    • UK insists negotiations over US tech deal still ‘active’
    • Aiarty Video Enhancer Update Adds New AI Models and Control Options – Get 36% Off Now
    • IAS Moves Beyond Verification With New AI Agent for Ad Campaign Optimizations
    Facebook X (Twitter) Instagram Pinterest Vimeo
    OnlyPlanz –OnlyPlanz –
    • Home
    • Marketing
    • Branding
    • Modeling
    • Video Creation
    • Editing Tips
    • Content
    • Engagement
    • More
      • Tools
      • Earnings
      • Legal
      • Monetization
    OnlyPlanz –
    Home»Tools»Phishers have found a way to downgrade—not bypass—FIDO MFA
    Tools

    Phishers have found a way to downgrade—not bypass—FIDO MFA

    onlyplanz_80y6mtBy onlyplanz_80y6mtJuly 19, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Phishers have found a way to downgrade—not bypass—FIDO MFA
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Expel stated that PoisonSeed has discovered a intelligent sleight of hand to bypass this important step. Because the consumer enters the username and password into the pretend Okta website, a PoisonSeed workforce member enters them in actual time into an actual Okta login web page. As Thursday’s publish went on to clarify:
    Within the case of this assault, the dangerous actors have entered the right username and password and requested cross-device sign-in. The login portal shows a QR code, which the phishing website instantly captures and relays again to the consumer on the pretend website. The consumer scans it with their MFA authenticator, the login portal and the MFA authenticator talk, and the attackers are in.
    This course of—whereas seemingly difficult—successfully bypasses any protections {that a} FIDO key grants, and provides the attackers entry to the compromised consumer’s account, together with entry to any purposes, delicate paperwork, and instruments such entry gives.
    How FIDO makes such assaults unimaginable
    The top consequence, the safety agency stated, was an adversary-in-the-middle assault that tampered with the QR code course of to bypass FIDO MFA. As famous earlier, writers of the FIDO spec anticipated such assault methods and constructed defenses that make them unimaginable, at the very least within the kind described by Expel. Had the focused Okta MFA course of adopted FIDO necessities, the login would have failed for at the very least two causes.
    First, the machine offering the hybrid type of authentication must be bodily shut sufficient to the attacker machine logging in for the 2 to attach over Bluetooth. Opposite to what Expel stated, this isn’t an “a further safety function.” It’s obligatory. With out it, the authentication will fail.
    Second, the problem the hybrid machine must signal can be certain to the area of the pretend website (right here okta[.]login-request[.]com) and never the real Okta.com area. Even when the hybrid machine was in shut proximity to the attacker machine, the authentication would nonetheless fail, for the reason that URLs don’t match.
    What Expel appears to have encountered is an assault that downgraded FIDO MFA with some weaker MFA kind. Very probably, this weaker authentication was just like these used to log in to a Netflix or YouTube account on a TV with a telephone. Assuming this was the case, the one that administered the group’s Okta login web page would have needed to intentionally select to permit this fallback to a weaker type of MFA. As such, the assault is extra precisely categorised as a FIDO downgrade assault, not a bypass.

    bypassFIDO downgradenot MFA Phishers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBehind Trump’s Jeffrey Epstein Problem
    Next Article Hints, Spangram And Answers For Sunday, July 20th
    onlyplanz_80y6mt
    • Website

    Related Posts

    Tools

    Instagram fixed an issue that caused posting multiple Stories to tank your reach

    September 13, 2025
    Tools

    Apple’s High Blood Pressure Alerts: When and Where They’ll Be Available

    September 13, 2025
    Tools

    Bullets Found After the Charlie Kirk Shooting Carried Messages. Here’s What They Mean

    September 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    5 Steps for Leading a Team You’ve Inherited

    June 18, 20255 Views

    Campbell’s VP Blasts Customers—And He’s Not the First Exec to Do It

    November 27, 20253 Views

    A Pro-Russia Disinformation Campaign Is Using Free AI Tools to Fuel a ‘Content Explosion’

    July 1, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Marketing

    Can Buzzy Marketing Bring Back JCPenney? CMO Marisa Thalberg Is Betting on It

    onlyplanz_80y6mtDecember 16, 2025
    Earnings

    Employment Rights Bill clears last parliamentary hurdle

    onlyplanz_80y6mtDecember 16, 2025
    Editing Tips

    Donald Trump sues BBC for up to $10bn over edit of January 6 speech | Donald Trump

    onlyplanz_80y6mtDecember 16, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    SLR reform is happening. Does it matter?

    June 18, 20250 Views

    Panthers in awe of Brad Marchand’s ‘will to win’ in Cup run

    June 18, 20250 Views

    DOJ Offers Divestiture Remedy in Lawsuit Opposing Merger of Defense Companies

    June 18, 20250 Views
    Our Picks

    Can Buzzy Marketing Bring Back JCPenney? CMO Marisa Thalberg Is Betting on It

    December 16, 2025

    Employment Rights Bill clears last parliamentary hurdle

    December 16, 2025

    Donald Trump sues BBC for up to $10bn over edit of January 6 speech | Donald Trump

    December 16, 2025
    Recent Posts
    • Can Buzzy Marketing Bring Back JCPenney? CMO Marisa Thalberg Is Betting on It
    • Employment Rights Bill clears last parliamentary hurdle
    • Donald Trump sues BBC for up to $10bn over edit of January 6 speech | Donald Trump
    • Godox launches updated and improved AD300 Pro II all-in-one outdoor flash
    • US lost 105,000 jobs in October and added 64,000 in November, according to delayed data | US economy
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 ThemeSphere. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.