Varonis found that an attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) as one of these external MFA providers and use it to insert a convincing Microsoft password prompt into the legitimate authentication flow.
The fake prompt captures the user’s password in plaintext before the malicious provider returns a valid signed token to Entra, causing the login to complete without displaying an error.
Yeah obviously if the account that configures the EAM is compromised then all bets are off. This isn’t exactly an attack is it, it’s just an observation about the trust model.
Those actions require a Global Administrator or Authentication Policy Administrator account, making TrustSink a post-compromise technique.
“If you’ve already been compromised then you’re fucked” isn’t the kind of research that deserves its own catchy name and blog post article. Is this what passes for security research these days?
I’d agree it certainly isn’t as big as they seem to convey. That being said, demonstrating that the blast radius of a compromise might be larger or harder to detect than thought is at least something.
You wouldn’t immediately assume that compromising an admin would allow a users password to be compromised via the 2fa system.
Definitely more “reason 24332456664 passwords aren’t the best” than “groundbreaking vulnerability”.
I call it cyberslop and it’s 99% of cybersecurity “news” nowadays. Just fearmongering of solved issues to advertise a product/service by the blog writer/hister/publisher.
Yeah obviously if the account that configures the EAM is compromised then all bets are off. This isn’t exactly an attack is it, it’s just an observation about the trust model.
“If you’ve already been compromised then you’re fucked” isn’t the kind of research that deserves its own catchy name and blog post article. Is this what passes for security research these days?
I’d agree it certainly isn’t as big as they seem to convey. That being said, demonstrating that the blast radius of a compromise might be larger or harder to detect than thought is at least something. You wouldn’t immediately assume that compromising an admin would allow a users password to be compromised via the 2fa system.
Definitely more “reason 24332456664 passwords aren’t the best” than “groundbreaking vulnerability”.
I call it cyberslop and it’s 99% of cybersecurity “news” nowadays. Just fearmongering of solved issues to advertise a product/service by the blog writer/hister/publisher.
Exactly my experience with varonis…