1<!doctype html> 2<html lang="en-us"> 3<head> 4 5<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/> 6<meta http-equiv="X-UA-Compatible" content="IE=edge" /> 7<meta name="viewport" content="width=device-width, initial-scale=1" /> 8 9 10<!-- Fonts --> 11<link href='https://fonts.googleapis.com/css?family=Roboto:400,100,300,500,700,900&display=swap' rel='stylesheet preload' type='text/css' as="style"> 12 13<!-- Style sheet --> 14<link href="https://www.bleepstatic.com/js/redesign/bootstrap/css/bootstrap.min.css" rel="stylesheet preload" type="text/css" media="all" as="style"> 15 16<link href="https://www.bleepstatic.com/css/redesign/main.css?v=12.03.25.1" rel="stylesheet preload" type="text/css" media="all" as="style"> 17<link href="https://www.bleepstatic.com/css/redesign/home.css" rel="stylesheet preload" type="text/css" media="screen" as="style"> 18<link href="https://www.bleepstatic.com/css/redesign/news.css" rel="stylesheet preload" type="text/css" as="style" media="screen,print"> 19<link rel="preload" href="https://www.bleepstatic.com/js/redesign/jquery-3.5.1.min.js" as="script"> 20 21<link rel="preload" href="https://www.bleepstatic.com/js/redesign/jquery-migrate-1.4.1.min.js" as="script"> 22 23<!-- Meta --> 24<meta name="Owner" content="Bleeping Computer, LLC." /> 25<link rel="shortcut icon" href="https://www.bleepstatic.com/favicon/bleeping.ico" /> 26<meta property="og:site_name" content="BleepingComputer" /> 27<meta property="og:locale" content="en_us" /> 28<meta name="application-name" content="BleepingComputer"/> 29<link rel='dns-prefetch' href='//fonts.googleapis.com'/> 30<link rel='dns-prefetch' href='//www.bleepstatic.com'/> 31<link rel='dns-prefetch' href='//www.google-analytics.com'/> 32<link rel='dns-prefetch' href='//www.googletagmanager.com'/> 33<link rel='dns-prefetch' href='//securepubads.g.doubleclick.net' /> 34 35<link rel="apple-touch-icon" href="https://www.bleepstatic.com/icons/apple-touch-icon.png" /> 36 37<title>Rogue external MFA providers can steal passwords during logins</title> 38 <meta name="Keywords" content="computers, windows, linux, mac, support, tech support, spyware, malware, virus, security, Credential Theft, Cybersecurity, MFA, Microsoft Entra, Multi-Factor Authentication,virus removal, malware removal, computer help, technical support" /> 39 <meta name="description" content="Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts." /> 40 <meta name="abstract" content="Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts." /> 41<link rel="canonical" href="https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/" /> 42<link rel="prev" href="https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/" /> 43<link rel="next" href="https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/" /> 44<meta name="news_keywords" content="Credential Theft, Cybersecurity, MFA, Microsoft Entra, Multi-Factor Authentication, Security, InfoSec, Computer Security"> 45 46<meta property="og:url" content="https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/" /> 47<meta property="og:type" content="article" /> 48<meta property="og:title" content="Rogue external MFA providers can steal passwords during logins" /> 49<meta property="article:content_tier" content="free" /> 50<meta property="og:description" content="Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts." /> 51<meta property="og:image" content="https://www.bleepstatic.com/content/hl-images/2022/09/19/MFA.jpg" /> 52<meta property="og:image:secure_url" content="https://www.bleepstatic.com/content/hl-images/2022/09/19/MFA.jpg" /> 53<meta property="fb:app_id" content="517620508265293" /> 54 55<meta property="og:image:width" content="1600" /> 56<meta property="og:image:height" content="900" /> 57 58<meta name="twitter:card" content="summary_large_image" /> 59<meta name="twitter:site" content="@BleepinComputer" /> 60<meta name="twitter:creator" content="@BleepinComputer" /> 61<meta name="twitter:title" content="Rogue external MFA providers can steal passwords during logins" /> 62<meta name="twitter:description" content="Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts." /> 63<meta name="twitter:image" content="https://www.bleepstatic.com/content/hl-images/2022/09/19/MFA.jpg" /> 64<meta name="fediverse:creator" content="@[email protected]" /> 65
66<script type="application/ld+json"> 67{ 68 "@context": "https://schema.org", 69 "@type": "NewsArticle", 70 "url": "https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/", 71 "headline": "Rogue external MFA providers can steal passwords during logins", 72 "name": "Rogue external MFA providers can steal passwords during logins", 73 "mainEntityOfPage": { 74 "@type": "WebPage", 75 "id": "https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/" 76 }, 77 "description": "Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts.", 78 "image": { 79 "@type": "ImageObject", 80 "url": "https://www.bleepstatic.com/content/hl-images/2022/09/19/MFA.jpg", 81 "width": 1600, 82 "height": 900 83 }, 84 "author": { 85 "@type": "Person", 86 "name": "Lawrence Abrams", 87 "url": "https://www.bleepingcomputer.com/author/lawrence-abrams/" 88 },
89 "keywords": ["Credential Theft","Cybersecurity","MFA","Microsoft Entra","Multi-Factor Authentication","Security","InfoSec, Computer Security"], 90 "datePublished": "2026-09-22T17:45:45-04:00", 91 "dateModified": "2026-09-22T17:45:45-04:00", 92 "publisher": { 93 "@type": "Organization", 94 "name": "BleepingComputer", 95 "url": "https://www.bleepingcomputer.com/", 96 "logo": { 97 "@type": "ImageObject", 98 "url": "https://www.bleepstatic.com/logos/bleepingcomputer-logo.png", 99 "width": 700, 100 "height": 700 101 } 102 } 103} 104</script>
104 105<link rel="amphtml" href="https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/amp/"> 106 107<LINK REL="alternate" TITLE="Bleeping Computer's News" HREF="https://www.bleepingcomputer.com/feed/" TYPE="application/rss+xml"> 108
109<script type="text/javascript" src="https://www.bleepstatic.com/js/redesign/jquery-3.5.1.min.js"></script>
vendor: 1 bytes, line 109
109
110<script type="text/javascript" src="https://www.bleepstatic.com/js/redesign/jquery-migrate-1.4.1.min.js"></script>
110 111
112<script async type="text/javascript" src="https://www.bleepstatic.com/js/redesign/news.js"></script>
vendor: 1 bytes, line 112
112
113<script>!function(n){if(!window.cnx){window.cnx={},window.cnx.cmd=[];var t=n.createElement('iframe');t.src='javascript:false'; t.display='none',t.onload=function(){var n=t.contentWindow.document,c=n.createElement('script');c.src='//cd.connatix.com/connatix.player.js?cid=f9509d53-804e-427d-a0bc-1204c0a3bcb1&pid=ce4d4c45-53cb-40cc-88d1-30d789f5b276',c.setAttribute('async','1'),c.setAttribute('type','text/javascript'),n.body.appendChild(c)},n.head.appendChild(t)}}(document);</script>
113 114
115<script id="9b67500bc68b4bf2997a1e7f878fb25e">(new Image()).src = 'https://capi.connatix.com/tr/si?token=ce4d4c45-53cb-40cc-88d1-30d789f5b276&cid=f9509d53-804e-427d-a0bc-1204c0a3bcb1'; cnx.cmd.push(function() { cnx({ playerId: "ce4d4c45-53cb-40cc-88d1-30d789f5b276" }).render("9b67500bc68b4bf2997a1e7f878fb25e"); });</script>
115 116 117<meta name="robots" content="max-image-preview:large"> 118 119<link rel="stylesheet" href="https://a.pub.network/bleepingcomputer-com/cls.css">
120<script data-cfasync="false" type="text/javascript"> 121 var freestar = freestar || {}; 122 freestar.queue = freestar.queue || []; 123 freestar.config = freestar.config || {}; 124 // Tag IDs set here, must match Tags served in the Body for proper setup 125 freestar.config.enabled_slots = []; 126 freestar.queue.push(function() { 127 128 googletag.pubads().setTargeting('section', ['news','security']); 129 freestar.deleteStickyFooter(); 130 freestar.deleteStickyFooter(); 131 }); 132 133 freestar.initCallback = function () { (freestar.config.enabled_slots.length === 0) ? freestar.initCallbackCalled = false : freestar.newAdSlots(freestar.config.enabled_slots) } 134</script>
vendor: 1 bytes, line 134
134
135<script src="https://a.pub.network/bleepingcomputer-com/pubfig.min.js" async></script>
135 136 137 138<!-- Google tag (gtag.js) -->
vendor: 64 bytes, lines 138-139
138 139<script async src="https://www.googletagmanager.com/gtag/js?id=
139G-GD465VRQLD
vendor: 12 bytes, line 139
139"></script>
140<script> 141
vendor: 134 bytes, lines 141-145
141window.dataLayer = window.dataLayer || []; 142 function gtag(){dataLayer.push(arguments);} 143 gtag('js', new Date()); 144 145 gtag('config', '
145G-GD465VRQLD
vendor: 4 bytes, line 145
145');
146</script>
146 147<!-- End GA --> 148 149 150 151</head> 152 153<body> 154 155 156 157<div class="bc_wrapper"> 158 159<!-- Start Header Section --> 160 161<header> 162 163 <div class="container"> 164 <div class="row"> 165 <div class="col-md-4"> 166 <a class="bc_logo" aria-label="BleepingComputer.com" href="https://www.bleepingcomputer.com/"><img src="https://www.bleepstatic.com/images/site/logo.png" width="287" height="24" alt="BleepingComputer.com logo"></a> 167 </div> 168 <div class="col-md-8"> 169 170 <ul class="bc_social_icons"> 171 <li><a href="https://www.facebook.com/BleepingComputer" aria-label="Visit BleepingComputer's Facebook profile"><span title="BleepingComputer Facebook page" class="fa-brands fa-facebook-f"></span></a></li> 172 <li><a href="https://twitter.com/BleepinComputer" aria-label="Visit BleepingComputer's Twitter profile"><span aria-hidden="true" title="BleepingComputer Twitter page" class="fa-brands fa-twitter"></span></a></li> 173 <li><a href="https://infosec.exchange/@BleepingComputer" aria-label="Visit BleepingComputer's Mastodon profile"><span aria-hidden="true" title="BleepingComputer Mastodon profile" class="fa-brands fa-mastodon"></span></a></li> 174 <li><a href="https://www.bleepingcomputer.com/feed/" aria-label="BleepingComputer's RSS Feeds"><span aria-hidden="true" title="RSS feed" class="fa fa-rss"></span></a></li> 175 </ul> 176 <div class="bc_search_box"> 177 <form title="Search site" action="https://www.bleepingcomputer.com/search/"> 178 <input type="hidden" name="cx" value="partner-pub-0920899300397823:3529943228" /> 179 <input type="hidden" name="cof" value="FORID:10" /> 180 <input type="hidden" name="ie" value="UTF-8" /> 181 <input type="search" name="q" aria-label="Search Site" placeholder="Search Site" /> 182 </form> 183
183<script async type="text/javascript" src="https://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
183 184 </div> 185 <div class="bc_login"> 186 <input aria-label="Login to BleepingComputer" type="submit" value="Login" class="bc_login_btn"> 187 <input aria-label="Register account" type="submit" value="Sign up" class="bc_signup_btn" onclick="window.location='https://www.bleepingcomputer.com/forums/index.php?app=core&module=global§ion=register';" /> 188 </div> 189 </div> 190 </div> 191 </div> 192 193 194 <!-- Start Navigation --> 195 196 <nav class="bc_navigation"> 197 <div class="container"> 198 199 <span id="toggle-nav" class="toggle-site-nav"> 200 <span></span> 201 </span> 202 <div class="site-nav" id="nav" role="navigation"> 203 <ul class="bc_social_icons bc_mob"> 204 <li><a href="https://www.facebook.com/BleepingComputer" aria-label="Visit BleepingComputer's Facebook profile"><span aria-hidden="true" class="fa-brands fa-facebook-f"></span></a></li> 205 <li><a href="https://twitter.com/BleepinComputer" aria-label="Visit BleepingComputer's Twitter profile"><span aria-hidden="true" class="fa-brands fa-twitter"></span></a></li> 206 <li><a href="https://infosec.exchange/@BleepingComputer" aria-label="Visit BleepingComputer's Mastodon profile"><span aria-hidden="true" title="BleepingComputer Mastodon profile" class="fa-brands fa-mastodon"></span></a></li> 207 <li><a href="https://www.bleepingcomputer.com/feed/" aria-label="BleepingComputer's RSS Feeds"><span aria-hidden="true" title="RSS feed" class="fa fa-rss"></span></a></li> 208 </ul> 209 <div class="bc_search_box bc_mob"> 210 <form action="https://www.bleepingcomputer.com/search/"> 211 <input type="hidden" name="cx" value="partner-pub-0920899300397823:3529943228" /> 212 <input type="hidden" name="cof" value="FORID:10" /> 213 <input type="hidden" name="ie" value="UTF-8" /> 214 <input type="search" name="q" aria-label="Search Site" placeholder="Search Site" /> 215 </form> 216
216<script async type="text/javascript" src="https://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
216 217 </div> 218 <div class="bc_login bc_mob"> 219 <input aria-label="Login to BleepingComputer" type="submit" value="Login" class="bc_login_btn"> 220 <input aria-label="Register account" type="submit" value="Sign up" class="bc_signup_btn" onclick="window.location='https://www.bleepingcomputer.com/forums/index.php?app=core&module=global§ion=register';"> 221 </div> 222 223 <ul class="nav-menu"> 224 225 <li class="bc_dropdown"><a href="https://www.bleepingcomputer.com/">News</a> 226 <div class="bc_sub_menu"> 227 <div role="tabpanel"> 228 <ul class="nav nav-tabs" role="tablist" id="bc_drop_tab"> 229 230 <li class="active"><a href="#nfeatured" role="tab" data-toggle="tab">Featured</a></li> 231 232 <li><a href="#nlatest" role="tab" data-toggle="tab">Latest</a></li> 233 234 </ul> 235 <div class="tab-content"> 236 237 <div role="tabpanel" class="tab-pane active" id="nfeatured"> 238 <ul> 239 240 <li> 241 <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/" class="nmic"> 242 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2022/12/16/thumb/211x130_FBI__headpic.jpg" alt="ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach" height="130px" width="100%"> 243 <p>ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach</p> 244 </a> 245 </li> 246 247 <li> 248 <a href="https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/" class="nmic"> 249 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2026/06/17/thumb/211x130_Microsoft-Defender.jpg" alt="New Windows Defender zero-day blocks Microsoft antivirus updates" height="130px" width="100%"> 250 <p>New Windows Defender zero-day blocks Microsoft antivirus updates</p> 251 </a> 252 </li> 253 254 <li> 255 <a href="https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/" class="nmic"> 256 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2026/09/22/thumb/211x130_phishing.jpg" alt="EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts" height="130px" width="100%"> 257 <p>EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts</p> 258 </a> 259 </li> 260 261 <li> 262 <a href="https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/" class="nmic"> 263 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2026/09/18/thumb/211x130_Check-Point.jpg" alt="Check Point warns of Management Server zero-day exploited in attacks" height="130px" width="100%"> 264 <p>Check Point warns of Management Server zero-day exploited in attacks</p> 265 </a> 266 </li> 267 268 </ul> 269 </div> 270 271 <div role="tabpanel" class="tab-pane" id="nlatest"> 272 <ul> 273 274 <li> 275 <a href="https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/" class="nmic"> 276 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2026/09/23/thumb/211x130_third-party-clickfix-red.jpg" alt="Placeholder domain used in dev docs now serves ClickFix attacks" height="130px" width="100%"> 277 <p>Placeholder domain used in dev docs now serves ClickFix attacks</p> 278 </a> 279 </li> 280 281 <li> 282 <a href="https://www.bleepingcomputer.com/news/security/new-remc
282ontrol-android-banking-malware-targets-users-in-europe-and-canada/" class="nmic"> 283 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2024/01/31/thumb/211x130_image_(2).jpg" alt="New RemControl Android banking malware targets users in Europe and Canada" height="130px" width="100%"> 284 <p>New RemControl Android banking malware targets users in Europe and Canada</p> 285 </a> 286 </li> 287 288 <li> 289 <a href="https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/" class="nmic"> 290 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2026/07/23/thumb/211x130_Check-Point.jpg" alt="Check Point warns of hackers exploiting Security Gateway VPN RCE flaw" height="130px" width="100%"> 291 <p>Check Point warns of hackers exploiting Security Gateway VPN RCE flaw</p> 292 </a> 293 </li> 294 295 <li> 296 <a href="https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/" class="nmic"> 297 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/hl-images/2025/11/03/thumb/211x130_WordPress.jpg" alt="Hackers start exploiting critical WordPress flaw for code execution" height="130px" width="100%"> 298 <p>Hackers start exploiting critical WordPress flaw for code execution</p> 299 </a> 300 </li> 301 302 </ul> 303 </div> 304 305 </div> 306 </div> 307 </div> 308 </li> 309 310 <li class="bc_dropdown"><a href="https://www.bleepingcomputer.com/tutorials/">Tutorials</a> 311 <div class="bc_sub_menu"> 312 <div role="tabpanel"> 313 <ul class="nav nav-tabs" role="tablist" id="bc_drop_tab"> 314 315 <li class="active"><a href="#tlatest" role="tab" data-toggle="tab">Latest</a></li> 316 317 <li><a href="#popular" role="tab" data-toggle="tab">Popular</a></li> 318 319 </ul> 320 <div class="tab-content"> 321 322 <div role="tabpanel" class="tab-pane active" id="tlatest"> 323 <ul> 324 325 <li> 326 <a href="/tutorials/how-to-access-the-dark-web-using-the-tor-browser/" class="nmic"> 327 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/7/375-Tor-headpic.jpg" alt="How to access the Dark Web using the Tor Browser" height="130px" width="100%"> 328 <p>How to access the Dark Web using the Tor Browser</p> 329 </a> 330 </li> 331 332 <li> 333 <a href="/tutorials/how-to-enable-kernel-mode-hardware-enforced-stack-protection-in-windows-11/" class="nmic"> 334 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/7/374-Microsoft_Defender_headpic.jpg" alt="How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11" height="130px" width="100%"> 335 <p>How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11</p> 336 </a> 337 </li> 338 339 <li> 340 <a href="/tutorials/how-to-use-the-windows-registry-editor/" class="nmic"> 341 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/7/371-windows-registry-editor.jpg" alt="How to use the Windows Registry Editor" height="130px" width="100%"> 342 <p>How to use the Windows Registry Editor</p> 343 </a> 344 </li> 345 346 <li> 347 <a href="/tutorials/how-to-backup-and-restore-the-windows-registry/" class="nmic"> 348 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/7/372-Windows.jpg" alt="How to backup and restore the Windows Registry" height="130px" width="100%"> 349 <p>How to backup and restore the Windows Registry</p> 350 </a> 351 </li> 352 353 </ul> 354 </div> 355 356 <div role="tabpanel" class="tab-pane" id="popular"> 357 <ul> 358 359 <li> 360 <a href="/tutorials/how-to-start-windows-in-safe-mode/" class="nmic"> 361 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/1/61-startup-settings.png" alt="How to start Windows in Safe Mode" height="130px" width="100%"> 362 <p>How to start Windows in Safe Mode</p> 363 </a> 364 </li> 365 366 <li> 367 <a href="/tutorials/how-to-remove-a-trojan-virus-worm-or-malware/" class="nmic"> 368 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/2/101-Cerber-wallpaper.png" alt="How to remove a Trojan, Virus, Worm, or other Malware" height="130px" width="100%"> 369 <p>How to remove a Trojan, Virus, Worm, or other Malware</p> 370 </a> 371 </li> 372 373 <li> 374 <a href="/tutorials/show-hidden-files-in-windows-7/" class="nmic"> 375 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/3/151-show-hidden-files.jpg" alt="How to show hidden files in Windows 7" height="130px" width="100%"> 376 <p>How to show hidden files in Windows 7</p> 377 </a> 378 </li> 379 380 <li> 381 <a href="/tutorials/how-to-see-hidden-files-in-windows/" class="nmic"> 382 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/site/tutorials/nav-header-images/1/62-hidden-files.jpg" alt="How to see hidden files in Windows" height="130px" width="100%"> 383 <p>How to see hidden files in Windows</p> 384 </a> 385 </li> 386 387 </ul> 388 </div> 389 390 </div> 391 </div> 392 </div> 393 </li> 394 <li><a href="https://www.bleepingcomputer.com/webinars/">Webinars</a></li> 395 <li class="bc_dropdown"><a href="https://www.bleepingcomputer.com/download/">Downloads</a> 396 <div class="bc_sub_menu"> 397 <div role="tabpanel"> 398 <ul class="nav nav-tabs" role="tablist" id="bc_drop_tab"> 399 400 <li class="active"><a href="#dlatest" role="tab" data-toggle="tab">Latest</a></li> 401 402 <li><a href="#most" role="tab" data-toggle="tab">Most Downloaded</a></li> 403 404 </ul> 405 <div class="tab-content"> 406 407 <div role="tabpanel" class="tab-pane active" id="dlatest"> 408 <ul> 409 410 <li> 411 <a href="https://www.bleepingcomputer.com/download/qualys-browsercheck/" class="nmic"> 412 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/2/201-qualys-browsercheck-for-windows.jpg" alt="Qualys BrowserCheck" height="130px" width="100%"> 413 <p class="center">Qualys BrowserCheck</p> 414 </a> 415 </li> 416 417 <li> 418 <a href="https://www.bleepingcomputer.com/download/stopdecrypter/" class="nmic"> 419 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/2/200-stopdecrypter.jpg" alt="STOPDecrypter" height="130px" width="100%"> 420 <p class="center">STOPDecrypter</p> 421 </a> 422 </li> 423 424 <li> 425 <a href="https://www.bleepingcomputer.com/download/auroradecrypter/" class="nmic"> 426 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/1/199-auroradecrypter.jpg" alt="AuroraDecrypter" height="130px" width="100%"> 427 <p class="center">AuroraDecrypter</p> 428 </a> 429 </li> 430 431 <li> 432 <a href="https://www.bleepingcomputer.com/download/fileslockerdecrypter/" class="nmic"> 433 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/1/198-fileslockerdecryptor.jpg" alt="FilesLockerDecrypter" height="130px" width="100%"> 434 <p class="center">FilesLockerDecrypter</p> 435 </a> 436 </li> 437 438 </ul> 439 </div> 440 441 <div role="tabpanel" class="tab-pane" id="most"> 442 <ul> 443 444 <li> 445 <a href="/download/adwcleaner/" class="nmic"> 446 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/0/96-adwcleaner.jpg" alt="AdwCleaner" height="130px" width="100%"> 447 <p class="center">AdwCleaner</p> 448 </a> 449 </li> 450 451 <li> 452 <a href="/download/combofix/" class="nmic"> 453 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/0/9-combofix.jpg" alt="ComboFix" height="130px" width="100%"> 454 <p class="center">ComboFix</p> 455 </a> 456 </li> 457 458 <li> 459 <a href="/download/rkill/" class="nmic"> 460 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/0/8-rkill.jpg" alt="RKill" height="130px" width="100%"> 461 <p class="center">RKill</p> 462 </a> 463 </li> 464 465 <li> 466 <a href="/download/junkware-removal-tool/" class="nmic"> 467 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/download/nav-header-images/0/98-junkware-removal-tool.jpg" alt="Junkware Removal Tool" height="130px" width="100%"> 468 <p class="center">Junkware Removal Tool</p> 469 </a> 470 </li> 471 472 </ul> 473 </div> 474 475 </div> 476 </div> 477 </div> 478 </li> 479 480 <li class="bc_dropdown"><a href="https://deals.bleepingcomputer.com/">Deals</a> 481 <div class="bc_sub_menu"> 482 <div role="tabpanel"> 483 <ul class="nav nav-tabs" role="tablist" id="bc_drop_tab"> 484 485 <li class="active"><a href="#dcategories" role="tab" data-toggle="tab">Categories</a></li> 486 487 </ul> 488 <div class="tab-content"> 489 490<div role="tabpanel" class="tab-pane active" id="dcategories"> 491 <ul> 492 493 <li> 494 <a href="https://deals.bleepingcomputer.com/deals/elearning?utm_source=bleepingcomputer.com&utm_medium=dd_cat"> 495 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/deals/elearning-nav.jpg" alt="eLearning" height="130px" width="100%"> 496 <p align='center'>eLearning</p> 497 </a> 498 </li> 499 500 <li> 501 <a href="https://deals.bleepingcomputer.com/deals/certifications?utm_source=bleepingcomputer.com&utm_medium=dd_cat"> 502 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/ima
502ges/deals/it-certification-nav.jpg" alt="IT Certification Courses" height="130px" width="100%"> 503 <p align='center'>IT Certification Courses</p> 504 </a> 505 </li> 506 507 <li> 508 <a href="https://deals.bleepingcomputer.com/deals/gear-gadgets?utm_source=bleepingcomputer.com&utm_medium=dd_cat"> 509 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="https://www.bleepstatic.com/images/deals/gear-gadgets-nav.jpg" class="b-lazy" alt="Gear & Gadgets" height="130px" width="100%"> 510 <p align='center'>Gear + Gadgets</p> 511 </a> 512 </li> 513 514 <li> 515 <a href="https://deals.bleepingcomputer.com/collections/tag-cyber-security?utm_source=bleepingcomputer.com&utm_medium=dd_cat"> 516 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="https://www.bleepstatic.com/images/deals/security-nav.jpg" class="b-lazy" alt="Security" height="130px" width="100%"> 517 <p align='center'>Security</p> 518 </a> 519 </li> 520 521 </ul> 522 </div> 523 524 </div> 525 </div> 526 </div> 527 </li> 528 529 <li class="bc_dropdown"><a href="https://www.bleepingcomputer.com/vpn/">VPNs</a> 530 <div class="bc_sub_menu"> 531 <div role="tabpanel"> 532 <ul class="nav nav-tabs" role="tablist" id="bc_drop_tab"> 533 534 <li class="active"><a href="#vpopular" role="tab" data-toggle="tab">Popular</a></li> 535 536 </ul> 537 <div class="tab-content"> 538 539 <div role="tabpanel" class="tab-pane active" id="vpopular"> 540 <ul> 541 542 <li> 543 <a href="https://www.bleepingcomputer.com/vpn/guides/best-vpn/" class="nmic"> 544 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2025/05/29/170x170_Best_VPN_services.jpg" alt="Best VPNs" height="130px" width="100%"> 545 <p>Best VPNs</p> 546 </a> 547 </li> 548 549 <li> 550 <a href="https://www.bleepingcomputer.com/vpn/guides/change-ip-address/" class="nmic"> 551 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2023/03/16/change_ip_address_(2).jpg" alt="How to change IP address" height="130px" width="100%"> 552 <p>How to change IP address</p> 553 </a> 554 </li> 555 556 <li> 557 <a href="https://www.bleepingcomputer.com/vpn/guides/access-dark-web-safely/" class="nmic"> 558 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2023/03/16/How_to_Access_the_Dark_Web_Safely_(1).jpg" alt="Access the dark web safely" height="130px" width="100%"> 559 <p>Access the dark web safely</p> 560 </a> 561 </li> 562 563 <li> 564 <a href="https://www.bleepingcomputer.com/vpn/guides/watch-youtube-tv-abroad-vpn/" class="nmic"> 565 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2023/03/24/How_to_wat
565ch_YouTube_TV_from_anywhere_with_a_VPN.jpg" alt="Best VPN for YouTube" height="130px" width="100%"> 566 <p>Best VPN for YouTube</p> 567 </a> 568 </li> 569 570 </ul> 571 </div> 572 573 </div> 574 </div> 575 </div> 576 </li> 577 578 <li><a href="https://www.bleepingcomputer.com/forums/">Forums</a></li> 579 <li class="bc_dropdown bc_more_nav"><a aria-label="Click here to see more BleepingComputer sections" id="more_dd" href="#">More</a> 580 <ul id="bc_more-nav" class="bc_more_submenu"> 581 <li><a href="https://www.bleepingcomputer.com/virus-removal/">Virus Removal Guides</a></li> 582 <li><a href="https://www.bleepingcomputer.com/startups/">Startup Database</a></li> 583 <li><a href="https://www.bleepingcomputer.com/uninstall/">Uninstall Database</a></li> 584 <li><a href="https://www.bleepingcomputer.com/glossary/">Glossary</a></li> 585 <li><a href="https://www.bleepingcomputer.com/news-tip/">Send us a Tip!</a></li> 586 <li><a href="https://www.bleepingcomputer.com/welcome-guide/">Welcome Guide</a></li> 587 </ul> 588 </li> 589 </ul> 590 </div> 591 </div> 592 </nav> 593 </header> 594<!-- End Header Section --> 595 596 597<section class="cz-oa-wrapp" id="wibble"> 598 <div class="container"> 599 <div class="row"> 600 <div class="col-md-12"> 601 <div class="cz-toa-wrapp"> 602 603<div align="center"> 604 <a href="https://ztw.com/?utm_source=bleeping_computer&utm_medium=sponsor&utm_campaign=join_the_global_cybersecurity_event_9-26&utm_content=join_the_global_cybersecurity_event-970x250&utm_term=display" rel="nofollow noopener" target="_blank"><img src="https://www.bleepstatic.com/c/t/tl-ztw-2027-970.jpg" width="970" height="auto" alt="ThreatLocker"></a> 605</div> 606 607 </div> 608 </div> 609 </div> 610 </div> 611</section> 612 613<section> 614 <div class="container"> 615 <div class="row"> 616 <div class="col-md-12"> 617 <div class="cz-breadcrumb-outer-wrapp"> 618 <div class="cz-breadcrumb-left-area"> 619 <div class="cz-breadcrumb"> 620 <ul itemscope itemtype="https://schema.org/BreadcrumbList"> 621 <li itemprop="itemListElement" itemscope itemtype="https://schema.org/ListItem"><a href="https://www.bleepingcomputer.com/" itemprop="item"><span itemprop="name">Home</span></a><meta itemprop="position" content="1" /></li><li itemprop="itemListElement" itemscope itemtype="https://schema.org/ListItem"><span itemprop="name"><a href="https://www.bleepingcomputer.com/news/" itemprop="item">News</a></span><meta itemprop="position" content="2" /></li><li itemprop="itemListElement" itemscope itemtype="https://schema.org/ListItem"><span itemprop="name"><a href="https://www.bleepingcomputer.com/news/security/" itemprop="item">Security</a></span><meta itemprop="position" content="3" /></li><li class="active" itemprop="itemListElement" itemscope itemtype="https://schema.org/ListItem"><span itemprop="name">Rogue external MFA providers can steal passwords during logins</span><meta itemprop="position" content="4" /></li> 622 </ul> 623 </div> 624 </div> 625 </div> 626 </div> 627 </div> 628 629 </div> 630</section> 631<!-- Start Content Section --> 632 633<section class="bc_main_content"> 634 <div class="container"> 635 <div class="row"> 636 <div class="col-md-8"> 637 <div class="cz-main-left-section"> 638 639<article><div class="article_section"> 640 <h1>Rogue external MFA providers can steal passwords during logins</h1> 641 <div class="cz-news-story-title-section"> 642 <div class="cz-news-title-left-area"> 643 By <h6><a rel="author" href="https://www.bleepingcomputer.com/author/lawrence-abrams/" class="author"><span itemprop="author" itemscope itemtype="https://schema.org/Person"><span itemprop="name">Lawrence Abrams</span></span></a></h6> 644 </div> 645 <meta itemprop="articleSection" content="Security"><div class="cz-news-title-right-area"> 646 <ul><li class="cz-news-date">September 22, 2026</li> 647 <li class="cz-news-time">05:45 PM</li> 648 649 <li class="cz-news-comment"><a href="#comment_form">0</a></li> 650 </ul></div> 651 </div> 652 <div class="articleBody"> 653 654<p style="text-align:center"><img alt="Authentication" height="900" src="https://www.bleepstatic.com/content/hl-images/2022/09/19/MFA.jpg" width="1600"></p> 655 656<p>Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts.</p> 657 658<p>The technique, dubbed TrustSink by Varonis Threat Labs, can work with any provider that relies on this external authentication model, though the researchers demonstrated the attack using Microsoft Entra.</p> 659 660<p>Microsoft Entra supports external MFA providers, which allow organizations to use third-party authentication services to satisfy multifactor authentication requests.</p> 661 662<p>
662According to <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-external-method-provider" target="_blank" rel="nofollow noopener">Microsoft</a>, when a user signs in with a first factor, such as a password, Entra can redirect them to an external MFA provider to complete the required second factor.</p> 663 664<p>If the provider returns a valid signed token indicating that the second factor was completed, Entra considers the MFA requirement satisfied.</p> 665 666<p>Varonis found that an attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) as one of these external MFA providers and use it to insert a convincing Microsoft password prompt into the legitimate authentication flow.</p> 667 668<p>The fake prompt captures the user's password in plaintext before the malicious provider returns a valid signed token to Entra, causing the login to complete without displaying an error.</p> 669 670<p>"In our test tenant, every sign-in completed normally while our server received passwords with timestamps and source IP addresses," <a href="http://www.varonis.com/blog/trustsink" target="_blank" rel="nofollow noopener">explains Varonis</a>.</p> 671 672<p>"Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user's next sign-in."</p> 673 674<p>It is important to note that TrustSink is not an initial-access attack and requires an attacker to already control a highly privileged Entra account.</p> 675 676<h2>Abusing an external MFA provider</h2> 677 678<p>TrustSink abuses the trust Microsoft places in a configured external MFA provider.</p> 679 680<p>Varonis created a malicious provider that appeared to Entra as a legitimate external MFA provider but displayed a copy of Microsoft's password page to the user.</p> 681 682<div style="text-align:center"> 683<figure class="image" style="display:inline-block"><img alt="The TrustSink attack" height="600" src="https://www.bleepstatic.com/images/news/security/t/trustsink/trustsink.jpg" width="593"><figcaption><strong>The TrustSink attack</strong></figcaption></figure></div> 684 685<p>During the proof-of-concept attack, the login initially proceeds normally, with the user entering their email address and password on Microsoft's legitimate login.microsoftonline.com site.</p> 686 687<p>When MFA is triggered, Entra redirects the browser to the attacker's external MFA provider for the second authentication step.</p> 688 689<p>Instead of presenting a legitimate second-factor challenge, the malicious provider displays a copy of Microsoft's password prompt.</p> 690 691<div style="text-align:center"> 692<figure class="image" style="display:inline-block"><img alt="External MFA provider showing a Microsoft login prompt" height="500" src="https://www.bleepstatic.com/images/news/security/t/trustsink/varonis-eam.jpg" width="936"><figcaption><strong>External MFA provider showing a Microsoft login prompt</strong><br><em>Source: Varonis</em></figcaption></figure></div> 693 694<p>If the victim enters their password again, believing Microsoft is requesting it as part of the authentication process, the credential is sent to the attacker-controlled server.</p> 695 696<p>The rogue provider then generates a signed token stating the MFA prompt was completed and returns it to Entra, allowing the user to continue to the application they originally attempted to access.</p> 697 698<p>From the victim's perspective, the sign-in appears to have completed normally.</p> 699 700<p>Varonis says the attack is convincing because the fake password prompt appears when the user already expects another authentication step.</p> 701 702<p>The researchers say the page uses the same fonts, layout, and button design as Microsoft's legitimate login page and appears immediately after the victim enters their real password on Microsoft's domain.</p> 703 704<p>Varonis says TrustSink builds on previous research by security researcher Dirk-Jan Mollema, presented at x33fcon 2025 in a talk titled <em>"<a href="https://www.youtube.com/watch?v=eKFgOtNpxwU" target="_blank" rel="nofollow noopener">Bringing Your Own Identity in Entra ID</a>."</em></p> 705 706<p>Mollema showed how a rogue registered external MFA provider could satisfy an MFA requirement by returning a signed JWT claiming authentication had succeeded without actually performing the expected authentication check.</p> 707 708<p>TrustSink abuses the same attack for credential theft.</p> 709 710<p>Varonis says registering the malicious external method requires modifying the Authentication Methods Policy and creating an application, service principal, and consent grant.</p> 711 712<p>Those actions require a Global Administrator or Authentication Policy Administrator account, making TrustSink a post-compromise technique.</p> 713 714<p>Once installed, however, the rogue provider can remain in the authentication path for targeted users across subsequent logins.</p> 715 716<p>Because the rogue MFA provider remains registered in the tenant's Authentication Methods Policy, even if a user changes their password, it will be recaptured on the next log in attempt.</p> 717 718<p>Varonis therefore warns administrators to remove the malicious provider before rotating affected credentials.</p> 719 720<p>Varonis recommends removing suspicious external MFA providers and their associated applications, keys, and redirect URIs before resetting affected users' passwords.</p> 721 722<p>Organizations should also monitor changes to the Authentication Methods Policy, limit standing Global Administrator and Authentication Policy Administrator privileges, and use phishing-resistant authentication methods such as FIDO2 or Windows Hello for Business.</p> 723 724 725<style> 726.article-callout { 727 background-color: #f0f6ff; 728 width: 95%; 729 max-width: 800px; 730 margin: 15px auto; 731 border-radius: 8px; 732 border: 1px solid #d6ddee; 733 display: flex; 734 align-items: stretch; 735 overflow: hidden; 736} 737 738.article-media { 739 flex: 1; 740 max-width: 220px; 741 display: flex; 742} 743 744.article-media a { 745 display: flex; 746 width: 100%; 747 height: 100%; 748} 749 750.article-media img { 751 width: 100%; 752 height: 100%; 753 754 border-radius: 8px 0 0 8px; 755 display: block; 756} 757 758.article-callout .article-media img { 759 margin-top: 0 !important; 760 height: 100% !important; 761} 762 763.article-body { 764 flex: 2; 765 padding: 10px; 766 display: flex; 767 flex-direction: column; 768 justify-content: center; 769} 770 771.article-body h2 { 772 font-size: 17px !important; 773 font-weight: 700; 774 color: #333; 775 line-height: 1.4; 776 font-family: Georgia, "Times New Roman", Times, serif; 777 margin: 0 0 14px 0; 778} 779 780.article-body p { 781 font-weight: bold; 782 font-size: 14px; 783 margin: 0 0 clamp(6px, 2vw, 14px) 0; 784} 785 786.article-link { 787 background-color: #fff; 788 border: 1px solid #3b59aa; 789 color: black; 790 text-align: center; 791 text-decoration: none; 792 border-radius: 8px; 793 display: inline-block; 794 font-size: 16px; 795 font-weight: bold; 796 padding: 10px 20px; 797 width: fit-content; 798} 799 800@media (max-width: 600px) { 801 .article-callout { 802 flex-direction: column; 803 align-items: center; 804 } 805 806 .article-media { 807 max-width: 100%; 808 } 809 810 .article-media img { 811 border-radius: 8px 8px 0 0; 812 } 813 814 .article-body { 815 padding: 15px; 816 width: 100%; 817 } 818 819 .article-link { 820 width: 100%; 821 margin: 0 auto; 822 box-sizing: border-box; 823 } 824} 825</style><div class="article-callout"> 826 <div class="article-media"> 827 <a href="https://hubs.li/Q04x67m50" target="_blank" rel="noopener nofollow"> 828 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" alt="article image" data-src="https://www.bleepstatic.com/c/p/validation-summit-2026.jpg" class="b-lazy"></a> 829 </div> 830 <div class="article-body"> 831 <h2> 832 <a href="https://hubs.li/Q04x67m50" target="_blank" rel="noopener nofollow">Build your security blueprint for AI-powered attacks</a> 833 </h2> 834 <p>Join Mikko Hyppö
834nen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.</p> 835 <a class="article-link" href="https://hubs.li/Q04x67m50" target="_blank" rel="noopener nofollow">Save your seat</a> 836 </div> 837</div> 838 839 840 <div class="cz-related-article-wrapp"> 841 <h3>Related Articles:</h3> 842 <p><a href="https://www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/" class="ras">39 New Methods That Compromise Passkey Authentication</a></p><p><a href="https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/" class="ras">MFA's Weakest Link: Account Recovery Is the New Attack Path</a></p><p><a href="https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/" class="ras">How AI-powered phishing killed blocklists for good</a></p><p><a href="https://www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/" class="ras">Is Your SSO Protected Against Modern Credential Attacks?</a></p><p><a href="https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/" class="ras">Placeholder domain used in dev docs now serves ClickFix attacks</a></p> 843 </div> 844 845 </div> 846 </div> 847 </article><div class="cz-news-tags-wrap"> 848 <ul><li><a href="https://www.bleepingcomputer.com/tag/credential-theft/">Credential Theft</a></li> 849 850 <li><a href="https://www.bleepingcomputer.com/tag/cybersecurity/">Cybersecurity</a></li> 851 852 <li><a href="https://www.bleepingcomputer.com/tag/mfa/">MFA</a></li> 853 854 <li><a href="https://www.bleepingcomputer.com/tag/microsoft-entra/">Microsoft Entra</a></li> 855 856 <li><a href="https://www.bleepingcomputer.com/tag/multi-factor-authentication/">Multi-Factor Authentication</a></li> 857 858 </ul></div> 859 860 <div class="cz-news-like-wrapp"> 861 <div class="addthis_toolbox addthis_default_style addthis_32x32_style"> 862 <div class="cz-news-like-left-area"> 863 <ul><li><a aria-label="Share article on Facebook" class="addthis_button_facebook"></a></li> 864 <li><a aria-label="Share article on Twitter" class="addthis_button_twitter"></a></li> 865 <li><a aria-label="Share article on LinkedIn" class="addthis_button_linkedin"></a></li> 866 </ul></div> 867 <div class="cz-news-like-right-area"> 868 <ul><li><a title="Email article" class="addthis_button_email"></a></li> 869 <li class="cz-lg-print-icon"><a aria-label="Print Article" title="Print article" href="#"></a></li> 870 </ul></div> 871 </div> 872 </div> 873 <div class="cz-full-bio-wrapp"> 874 <div class="cz-full-bio-img-wrapp" title="Lawrence Abrams profile page"> 875 <a style="background-image:url('https://www.bleepstatic.com/author/photos/21beb902b545b086a90ec39f1df36b94.jpg');" aria-label="Photo of Lawrence Abrams" alt-title="Lawrence Abrams profile page" class="author-img" href="https://www.bleepingcomputer.com/author/lawrence-abrams/"></a> 876 </div> 877 <div class="cz-full-bio-content-wrapp"> 878 <h5><a href="https://www.bleepingcomputer.com/author/lawrence-abrams/" target="_blank">Lawrence Abrams</a> <span> <a href="mailto:[email protected]" aria-label="Email [email protected]" alt-title="Email [email protected]"><i aria-hidden="true" class="fa fa-envelope email" title="Email [email protected]"></i></a> <a href="https://twitter.com/LawrenceAbrams" target="_blank" rel="noopener" aria-label="Open Author's twitter page" alt-title="Open Author's twitter page"><i aria-hidden="true" class="fa-brands fa-twitter twitter" title="Open Author's twitter page"></i></a></span></h5> 879 Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies. 880 </div> 881 </div> 882 883 884 <div class="cz-story-navigation"> 885 <ul><li><a href="https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/"><i aria-hidden="true" title="Previous story" class="fa fa-chevron-left"></i> Previous Article </a></li> 886 887 <li><a href="https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/">Next Article <i aria-hidden="true" title="Next story" class="fa fa-chevron-right"></i></a></li> 888 889 </ul></div> 890 891 892 893 <div class="cz-post-comment-wrapp" id="comment_form"> 894 <h5>Post a Comment <span><a href="https://www.bleepingcomputer.com/posting-guidelines/" target="_blank">Community Rules</a></span></h5> 895 <div class="cz-comment-loggin-wrapp"> 896 <h6>You need to login in order to post a comment</h6> 897 <input type="submit" value="Login" class="bc_login_btn cz-green-bttn"><p>Not a member yet? <a href="https://www.bleepingcomputer.com/forums/index.php?app=core&module=global&section=register">Register Now</a></p> 898 </div> 899 </div> 900 901 <div class="cz-related-article-wrapp"> 902 <h3>You may also like:</h3>
903<script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>
903<ins class="adsbygoogle" style="display:block" data-ad-format="autorelaxed" data-ad-client="ca-pub-0920899300397823" data-ad-slot="4359266829"></ins>
904<script> 905 (adsbygoogle = window.adsbygoogle || []).push({}); 906</script>
906</div> 907 908 </div> 909 </div> 910 911 <!-- side bar section --> 912 <div class="col-md-4 bc_right_sidebar"> 913 914 915 916 917 918 <div> 919 920<div align="center"> 921 <a href="https://ztw.com/?utm_source=bleeping_computer&utm_medium=sponsor&utm_campaign=join_the_global_cybersecurity_event_9-26&utm_content=join_the_global_cybersecurity_event-400x500&utm_term=display" rel="nofollow noopener" target="_blank"><img src="https://www.bleepstatic.com/c/t/tl-ztw-2027-400.jpg" alt="ThreatLocker" width="400px" height="auto"></a> 922</div> 923 924</div> 925 926 927 928 <div align="center" style="margin-top:10px;"><div class="cz-line-heading"><div class="cz-line-heading-inner"> Upcoming Webinar</div></div> <a href="/rd/99/" rel="nofollow noopener" target="_blank"><img src="https://www.bleepstatic.com/c/m/material-400.jpg" alt="Webinar" width="400px" height="auto"></a></div> 929 <div id="pop_stories"> 930 <div class="cz-line-heading"><div class="cz-line-heading-inner">Popular Stories</div></div> 931 <ul> 932 933 <li> 934 <a class="pns" href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/"> 935 <div class="bc_pop_story_img)"> 936 <img class="b-lazy" alt="FBI" src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="https://www.bleepstatic.com/content/hl-images/2022/12/16/thumb/292x176_FBI__headpic.jpg"> 937 </div> 938 <p>ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach</p> 939 </a> 940 </li> 941 942 <li> 943 <a class="pns" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/"> 944 <div class="bc_pop_story_img)"> 945 <img class="b-lazy" alt="Hacking login" src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="https://www.bleepstatic.com/content/hl-images/2026/03/12/thumb/292x176_Hacking_login.jpg"> 946 </div> 947 <p>Microsoft reminds admins to migrate Entra ID users to passkeys</p> 948 </a> 949 </li> 950 951 <li> 952 <a class="pns" href="https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/"> 953 <div class="bc_pop_story_img)"> 954 <img class="b-lazy" alt="Microsoft Defender" src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="https://www.bleepstatic.com/content/hl-images/2026/06/17/thumb/292x176_Microsoft-Defender.jpg"> 955 </div> 956 <p>New Windows Defender zero-day blocks Microsoft antivirus updates</p> 957 </a> 958 </li> 959 960 </ul> 961 </div> 962 963 964 <div> 965 <div class="bc-heading"><div class="bc-heading-inner"><span>S</span>ponsor Posts</div></div> 966 <ul style="padding-top:5px;"> 967 968 <li> 969 <a class="spon_res" href="https://www.tenfold-security.com/en/take-in-browser-tour/?utm_source=bleepingcomputer&utm_medium=referral&utm_campaign=bleepingcomputer_referral&utm_content=article" target="_blank" rel="nofollow noopener"> 970 <div class="bc_guide_img"> 971 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/news/security/t/tenfold/fileserver/tenfold-sidebar.jpg" alt="Automate Onboarding and Access Reviews with No-Code IGA: See how it works"> 972 </div> 973 <div class="bc_guide_text"> 974 <p>Automate Onboarding and Access Reviews with No-Code IGA: See how it works</p> 975 </div> 976 </a> 977 </li> 978 979 <li> 980 <a class="spon_res" href="https://info.varonis.com/en/state-of-data-security-report-2025?utm_source=bleepingcomputer&utm_medium=referral&utm_campaign=bleepingcomputer_referral&utm_content=article" target="_blank" rel="nofollow noopener"> 981 <div class="bc_guide_img"> 982 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2026/09/22/thumb/100x82_screwdriver-stealing-card.jpg" alt="AI is a data-breach time bomb: Read the new report"> 983 </div> 984 <div class="bc_guide_text"> 985 <p>AI is a data-breach time bomb: Read the new report</p> 986 </div> 987 </a> 988 </li> 989 990 <li> 991 <a class="spon_res" href="https://specopssoft.com/product/specops-password-auditor/?utm_source=bleepingcomputer&utm_medium=referral&utm_campaign=infinipoint_bleepingcomputer_referral_na&utm_content=article" target="_blank" rel="nofollow noopener"> 992 <div class="bc_guide_img"> 993 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2026/09/09/thumb/100x82_specops-hands-typing.jpg" alt="Overdue a password health-check? Audit your Active Directory for free"> 994 </div> 995 <div class="bc_guide_text"> 996 <p>Overdue a password health-check? Audit your Active Directory for free</p> 997 </div> 998 </a> 999 </li> 1000 1001 <li> 1002 <a class="spon_res" href="https://wazuh.com/?utm_source=bleepingcomputer.com&utm_medium=referral&utm_campaign=wazuh_bleepingcomputer" target="_blank" rel="nofollow noopener"> 1003 <div class="bc_guide_img"> 1004 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/images/news/security/w/wazuh/wazuh-square.jpg" alt="Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection"> 1005 </div> 1006 <div class="bc_guide_text"> 1007 <p>
1007Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection</p> 1008 </div> 1009 </a> 1010 </li> 1011 1012 <li> 1013 <a class="spon_res" href="https://specopssoft.com/product/specops-password-auditor/?utm_source=bleepingcomputer&utm_medium=referral&utm_campaign=bleepingcomputer_referral_na&utm_content=article" target="_blank" rel="nofollow noopener"> 1014 <div class="bc_guide_img"> 1015 <img src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" class="b-lazy" data-src="https://www.bleepstatic.com/content/posts/2026/09/14/thumb/100x82_specops-legal-doc.jpg" alt="Overdue a password health-check? Audit your Active Directory for free"> 1016 </div> 1017 <div class="bc_guide_text"> 1018 <p>Overdue a password health-check? Audit your Active Directory for free</p> 1019 </div> 1020 </a> 1021 </li> 1022 1023 </ul> 1024 </div> 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 <div class="s-ou-wrap" id="RI4Bm2Ka"> 1035 1036<div align="center" data-freestar-ad="__300x250 __300x600" id="bleepingcomputer_300x250_300x600_160x600_Right_3">
1037<script data-cfasync="false" type="text/javascript"> 1038 freestar.config.enabled_slots.push({ placementName: "bleepingcomputer_300x250_300x600_160x600_Right_3", slotId: "bleepingcomputer_300x250_300x600_160x600_Right_3" }); 1039</script>
1039 1040</div> 1041 1042</div> 1043 </div> 1044 </div> 1045 </div> 1046</section> 1047 1048<!-- End Content Section --> 1049<section class="cz-boa-wrapp"> 1050 <div class="container"> 1051 <div class="row"> 1052 <div class="col-md-12"> 1053 1054<div align="center" data-freestar-ad="__300x50 __970x250" id="bleepingcomputer_728x90_970x90_970x250_320x50_BTF">
1055<script data-cfasync="false" type="text/javascript"> 1056 freestar.config.enabled_slots.push({ placementName: "bleepingcomputer_728x90_970x90_970x250_320x50_BTF", slotId: "bleepingcomputer_728x90_970x90_970x250_320x50_BTF" }); 1057</script>
1057 1058</div> 1059 1060 </div> 1061 </div> 1062 </div> 1063</section> 1064<!-- Start Footer Section --> 1065 1066<footer id="footer"> 1067 <div class="container"> 1068 <div class="row"> 1069 <div class="col-md-4"> 1070 1071 1072 <h5>Follow us:</h5> 1073 <ul class="bc_social_icons"> 1074 <li><a href="https://www.facebook.com/BleepingComputer" aria-label="Visit BleepingComputer's Facebook page"><span aria-hidden="true" class="fa-brands fa-facebook-f"></span></a></li> 1075 <li><a href="https://twitter.com/BleepinComputer" aria-label="Visit BleepingComputer's Twitter page"><span aria-hidden="true" class="fa-brands fa-twitter"></span></a></li> 1076 <li><a href="https://infosec.exchange/@BleepingComputer" aria-label="Visit BleepingComputer's Mastodon profile"><span aria-hidden="true" title="BleepingComputer Mastodon profile" class="fa-brands fa-mastodon"></span></a></li> 1077 <li><a href="https://www.youtube.com/user/BleepingComputer" aria-label="Visit BleepingComputer's YouTube page"><span aria-hidden="true" class="fa-brands fa-youtube"></span></a></li> 1078 <li><a href="https://www.bleepingcomputer.com/feed/" aria-label="BleepingComputer's RSS Feeds"><span aria-hidden="true" class="fa fa-rss"></span></a></li> 1079 </ul> 1080 1081 </div> 1082 <div class="col-md-2"> 1083 <h5>Main Sections</h5> 1084 <ul> 1085 <li><a href="https://www.bleepingcomputer.com/">News</a></li> 1086 <li><a href="https://www.bleepingcomputer.com/webinars/">Webinars</a></li> 1087 <li><a href="https://www.bleepingcomputer.com/vpn/">VPN Buyer Guides</a></li> 1088 <li><a href="https://www.bleepingcomputer.com/sysadmin/">SysAdmin Software Guides</a></li> 1089 <li><a href="https://www.bleepingcomputer.com/download/">Downloads</a></li> 1090 <li><a href="https://www.bleepingcomputer.com/virus-removal/">Virus Removal Guides</a></li> 1091 <li><a href="https://www.bleepingcomputer.com/tutorials/">Tutorials</a></li> 1092 <li><a href="https://www.bleepingcomputer.com/startups/">Startup Database</a></li> 1093 <li><a href="https://www.bleepingcomputer.com/uninstall/">Uninstall Database</a></li> 1094 <li><a href="https://www.bleepingcomputer.com/glossary/">Glossary</a></li> 1095 </ul> 1096 </div> 1097 <div class="col-md-2"> 1098 <h5>Community</h5> 1099 <ul> 1100 <li><a href="https://www.bleepingcomputer.com/forums/">Forums</a></li> 1101 <li><a href="https://www.bleepingcomputer.com/forum-rules/">Forum Rules</a></li> 1102 <li><a href="https://www.bleepingcomputer.com/forums/t/730914/the-bleepingcomputer-official-discord-chat-server-come-join-the-fun/">Chat</a></li> 1103 </ul> 1104 </div> 1105 <div class="col-md-2"> 1106 <h5>Useful Resources</h5> 1107 <ul> 1108 <li><a href="https://www.bleepingcomputer.com/welcome-guide/">Welcome Guide</a></li> 1109 <li><a href="https://www.bleepingcomputer.com/sitemap/">Sitemap</a></li> 1110 </ul> 1111 </div> 1112 <div class="col-md-2"> 1113 <h5>Company</h5> 1114 <ul> 1115 <li><a href="https://www.bleepingcomputer.com/about/">About BleepingComputer</a></li> 1116 <li><a href="https://www.bleepingcomputer.com/contact/">Contact Us</a></li> 1117 <li><a href="https://www.bleepingcomputer.com/news-tip/">Send us a Tip!</a></li> 1118 <li><a href="https://www.bleepingcomputer.com/advertise/">Advertising</a></li> 1119 <li><a href="https://www.bleepingcomputer.com/write-for-bleepingcomputer/">Write for BleepingComputer</a></li> 1120 <li><a href="https://www.bleepingcomputer.com/rss-feeds/">Social & Feeds</a></li> 1121 <li><a href="https://www.bleepingcomputer.com/changelog/">Changelog</a></li> 1122 </ul> 1123 </div> 1124 </div> 1125 </div> 1126 <div class="bc_footer_bottom"> 1127 <div class="container"> 1128 <div class="row"> 1129 <div class="col-md-6"> 1130 <p><a href="https://www.bleepingcomputer.com/terms-of-use/">Terms of Use</a> - <a href="https://www.bleepingcomputer.com/privacy/"> Privacy Policy</a> - <a href="https://www.bleepingcomputer.com/ethics-statement/">Ethics Statement</a> - <a href="https://www.bleepingcomputer.com/affiliate-disclosure/">Affiliate Disclosure</a></p> 1131 </div> 1132 <div class="col-md-6 bc_copyright"> 1133 <p>Copyright @ 2003 - 2026 <a href="https://www.bleepingcomputer.com/"> Bleeping Computer<sup>®</sup> LLC </a> - All Rights Reserved</p> 1134 </div> 1135 </div> 1136 </div> 1137 </div> 1138</footer> 1139</div> 1140<!-- End Footer Section --> 1141 1142<!-- Start Go to top Section --> 1143 1144<div class="bc_goto_top"> 1145 <a href="#" title="Back to Top"><i aria-hidden="true" class="fa fa-chevron-up"></i></a> 1146</div> 1147 1148<!-- End Go to top Section --> 1149 1150 1151<!-- Start Popup Section --> 1152 1153<div class="bc_popup" aria-modal="true" aria-label="Login form"> 1154 <div class="bc_login_form"> 1155 <a class="bc_popup_close" href="javascript:;" aria-label="Close login form" title="Close"></a> 1156 <h4>Login</h4> 1157 <form action="https://www.bleepingcomputer.com/forums/index.php?app=core&module=global&section=login&do=process&return=https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/" method="post"> 1158 <div class="bc_form_feild"> 1159 <label for="ips_username">Username</label> 1160 <input aria-label="Enter login name" title="Enter login name" type="text" id="ips_username" name="ips_username" spellcheck="false" autocomplete="username"> 1161 </div> 1162 <div class="bc_form_feild"> 1163 <label for="ips_password">Password</label> 1164 <input aria-label="Enter login password" title="Enter login passwod" type="password" id="ips_password" name="ips_password" spellcheck="false" autocomplete="current-password"> 1165 </div> 1166 <div class="bc_form_feild"> 1167 <div class="bc_remember"> 1168 <input id="remember" type="checkbox" name="rememberMe" value="1" checked="checked"> 1169 <label for="remember">Remember Me</label> 1170 </div> 1171 <div class="bc_anon"> 1172 <input id="anonymous" type="checkbox" name="anonymous" value="1"> 1173 <label for="anonymous">Sign in anonymously</label> 1174 </div> 1175 </div> 1176 <div class="bc_btn_wrap"> 1177 <input type='hidden' name='auth_key' value='880ea6a14ea49e853634fbdc5015a024' /> 1178 <input type="submit" aria-label="Login to site" title="Login" value="Login" class="bc_sub_btn"> 1179 <a aria-label="Sign in with Twitter" href="https://www.bleepingcomputer.com/forums/index.php?app=core&module=global&section=login&serviceClick=twitter&return=https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/" class="bc_twitter_btn"><img src="https://www.bleepstatic.com/images/site/login/twitter.png" width="28" height="24" alt="Sign in with Twitter button"> Sign in with Twitter</a> 1180 <hr /> 1181 <p>Not a member yet? <a aria-label="Register account" title="Register account" href="https://www.bleepingcomputer.com/forums/index.php?app=core&module=global§ion=register">Register Now</a></p> 1182 </div> 1183 </form> 1184 </div> 1185</div> 1186 1187<!-- End Popup Section --> 1188 1189 1190<!-- Script -->
1191<script async type="text/javascript" src="https://www.bleepstatic.com/js/redesign/bootstrap/js/bootstrap.js"></script>
vendor: 1 bytes, line 1191
1191
1192<script src="https://www.bleepstatic.com/js/blazy/blazy.min.js"></script>
vendor: 1 bytes, line 1192
1192
1193<script type="text/javascript" async src="https://www.bleepstatic.com/js/redesign/bleep.js"></script>
1193 1194
1195<script type="text/javascript" async defer src="https://www.bleepstatic.com/js/redesign/fancybox/jquery.fancybox.js"></script>
vendor: 1 bytes, line 1195
1195
1196<script type="text/jscript"> 1197$(document).ready(function(e) { 1198 $('.articleBody img').not('a>img').not('.contrib_but>img').click(function(e) { 1199 e.preventDefault(); 1200 $.fancybox({'href' : $(this).attr('src')}); 1201 }); 1202}); 1203</script>
1203 1204
1205<script src="//www.bleepstatic.com/js/fixto/fixto.min.js"></script>
1205 1206
1207<script type="text/javascript"> 1208$(document).ready(function(){ 1209 1210var content = $('.cz-main-left-section'); 1211var sidebar = $('.bc_right_sidebar'); 1212var count = 0; 1213var myTimer; 1214 1215function setEqualContainer() { 1216 var getContentHeight = content.outerHeight(); 1217 var getSidebarHeight = sidebar.outerHeight(); 1218 1219 if ( getContentHeight > getSidebarHeight ) { 1220 sidebar.css('min-height', getContentHeight); 1221 } 1222 1223 if ( getSidebarHeight > getContentHeight ) { 1224 content.css('min-height', getSidebarHeight); 1225 } 1226} 1227 1228// creating the timer which will run every 500 milliseconds 1229// and will stop after the container will be loaded 1230// ...or after 15 seconds to not eat a lot of memory 1231 1232myTimer = setInterval( function() { 1233 count++; 1234 1235 if ( $('.testContainer').length == 0 ) { 1236 setEqualContainer(); 1237 } else { 1238 setEqualContainer(); 1239 clearInterval(myTimer); 1240 } 1241 1242 if ( count == 15) { 1243 clearInterval(myTimer); 1244 } 1245}, 500); 1246 1247 $('#RI4Bm2Ka').fixTo('.bc_right_sidebar', { 1248 top: 25, 1249 bottom: 25, 1250 }); 1251 1252 $('#more_dd').click(function (e) { 1253 e.preventDefault() 1254 }); 1255 1256 $('.bc_goto_top a').click(function(){ 1257 $("html, body").animate({ scrollTop: 0 }, 600); 1258 return false; 1259 }); 1260 jQuery('.bc_login_btn').on('click', function() { 1261 jQuery('.bc_popup').fadeIn("slow"); 1262 }); 1263 jQuery('.bc_popup_close').on('click', function() { 1264 jQuery('.bc_popup').fadeOut("slow"); 1265 }); 1266 1267}); 1268</script>
vendor: 1 bytes, line 1268
1268
1269<script type="text/javascript"> 1270// validate comment box not empty 1271function validate_comment_box_not_empty() 1272{ 1273 $('#frm_comment_box').submit(function(e) { 1274 if($('#comment_html_box').val().length==0) 1275 { 1276 alert("Please enter a comment before pressing submit"); 1277 return false; 1278 } 1279 else 1280 { 1281 return true; 1282 } 1283 }); 1284} 1285 1286function cz_strip_tags(input, allowed) { 1287 allowed = (((allowed || '') + '') 1288 .toLowerCase() 1289 .match(/<[a-z][a-z0-9]*>/g) || []) 1290 .join(''); // making sure the allowed arg is a string containing only tags in lowercase (<a><b><c>) 1291 var tags = /<\/?([a-z][a-z0-9]*)\b[^>]*>/gi, 1292 commentsAndPhpTags = /<!--[\s\S]*?-->|<\?(?:php)?[\s\S]*?\?>/gi; 1293 return input.replace(commentsAndPhpTags, '') 1294 .replace(tags, function($0, $1) { 1295 return allowed.indexOf('<' + $1.toLowerCase() + '>') > -1 ? $0 : ''; 1296 }); 1297} 1298function cz_br2nl(str) { 1299 var regex = /<br\s*[\/]?>/gi; 1300 //var pure_str = str.replace(regex,"\n"); 1301 var pure_str = str.replace(regex,""); 1302 return cz_strip_tags(pure_str,''); 1303} 1304$(document).ready(function(e) { 1305// validate comment box not empty 1306validate_comment_box_not_empty(); 1307 1308// report comment 1309$('#comment-report-other-reason-wrap').css('display','none'); 1310$('.cz-popup-close').click(function(e) { 1311 e.preventDefault(); 1312 $('.cz-popup').fadeOut("slow"); 1313}); 1314$('.cz-comment-report-btn').click(function(e) { 1315 e.preventDefault(); 1316 $('.cz-popup').css('height',$( document ).height()+'px'); 1317 //var comment_box_report_top = $(this).offset().top; 1318 var comment_box_report_top = $(document).scrollTop(); 1319 $('.cz-popup-wrapp').css('top',(comment_box_report_top+100)+'px'); 1320 $('#comment-id-report').val($(this).attr('data-id')); 1321 $('.cz-popup').fadeIn("slow"); 1322}); 1323$("input[type='radio'][name='comment-report-reason']").click(function(e) { 1324 if($(this).val()=='Other') 1325 { 1326 $('#comment-report-other-reason-wrap').css('display','block'); 1327 } 1328 else 1329 { 1330 $('#comment-report-other-reason-wrap').css('display','none'); 1331 } 1332}); 1333$('.comment-report-submit-btn').click(function(e) { 1334 e.preventDefault(); 1335 var comment_report_reason = ""; 1336 var comment_report_reason = $("input[type='radio'][name='comment-report-reason']:checked").val(); 1337 if (comment_report_reason=='Other') { 1338 comment_report_reason = $('#comment-report-other-reason').val(); 1339 } 1340 if(comment_report_reason=='') { 1341 alert('Please specify reason'); 1342 } 1343 else 1344 { 1345 $('.cz-popup-report-submiting').css('display','inline-block'); 1346 $.ajax({ 1347 1348 type: "POST", 1349 url: 'https://www.bleepingcomputer.com/report-comment/', 1350 data: { comment_id: $('#comment-id-report').val(), reason: comment_report_reason, csrf_token: 'e057e1959c875d15259101ea49a91fd2f3aaed982cd8e595ef25b4eae6d7b68f' }, 1351 success: function(data) { 1352 $('.cz-popup-report-submiting').css('display','none'); 1353 $('.cz-popup').fadeOut("slow"); 1354 } 1355 1356 }); 1357 } 1358}); 1359// report comment 1360 1361 $('.cz_comment_reply_btn').click(function(e) { 1362 e.preventDefault(); 1363 $('#parent_comment_id').val($(this).attr('data-id')); 1364 $('#comment_html_box').attr('placeholder','Replying to '+$(this).attr('data-name')); 1365 var comment_box_top = $('.cz-post-comment-wrapp').offset().top; 1366 $("html, body").animate({ scrollTop: comment_box_top-100 }, 600); 1367 $('#comment_html_box').focus(); 1368 }); 1369 $('.cz_comment_quote_btn').click(function(e) { 1370 e.preventDefault(); 1371 var quote_comment_html =''; 1372 if($(this).attr('data-id')!=undefined && $(this).attr('data-id')!='') 1373 { 1374 $('#parent_comment_id').val($(this).attr('data-id')); 1375 quote_comment_html = $('#comment_html_'+$(this).attr('data-id')).html(); 1376 } 1377 quote_comment_html = cz_br2nl(quote_comment_html); 1378 $('#comment_html_box').val('"'+quote_comment_html+'"\n\n'); 1379 var comment_box_top = $('.cz-post-comment-wrapp').offset().top; 1380 $("html, body").animate({ scrollTop: comment_box_top-100 }, 600); 1381 $('#comment_html_box').focus(); 1382 }); 1383 1384}); 1385 1386function editForm(cid) 1387{ 1388 1389 $.ajax({ 1390 1391 type: "GET", 1392 url: window.location.href+"?sa=1", 1393 data: { f: "e", cid: cid }, 1394 success: function(data) { 1395 if (data && data.trim().length) { 1396 $('.cz-post-comment-wrapp').html(data); 1397 validate_comment_box_not_empty(); 1398 } 1399 }, 1400 error: function() { 1401 } 1402 1403 }); 1404 1405 var comment_box_top = $('.cz-post-comment-wrapp').offset().top; 1406 $("html, body").animate({ scrollTop: comment_box_top-100 }, 600); 1407 1408} 1409 1410$(document).on('click', '.cz-subscribe-button' , function(e) { 1411 e.preventDefault(); 1412 1413 $.ajax({ 1414 1415 type: "POST", 1416 url: window.location.href,
1417 data: { a: 'sub', csrf_token: 'e057e1959c875d15259101ea49a91fd2f3aaed982cd8e595ef25b4eae6d7b68f' }, 1418 success: function(data) { 1419 if(data == '1') 1420 $( "li.cz-subscribe-button" ).replaceWith( '<li aria-label="Unsubscribe from comments" title="Unsubscribe from comments" class="cz-unsubscribe-button"><a href="#"></a></li>'); 1421 } 1422 1423 }); 1424}); 1425 1426$(document).on('click', '.cz-unsubscribe-button' , function(e) { 1427 e.preventDefault(); 1428 1429 $.ajax({ 1430 1431 type: "POST", 1432 url: window.location.href, 1433 data: { a: 'unsub', csrf_token: 'e057e1959c875d15259101ea49a91fd2f3aaed982cd8e595ef25b4eae6d7b68f' }, 1434 success: function(data) { 1435 if(data == '1') 1436 $( "li.cz-unsubscribe-button" ).replaceWith( '<li aria-label="Subscribe to comments" title="Subscribe to comments" class="cz-subscribe-button"><a href="#"></a></li>'); 1437 } 1438 1439 }); 1440 1441}); 1442</script>
1442 1443
1444<script type="text/javascript"> 1445$('.cz-print-icon, .cz-lg-print-icon').click(function(e) { 1446 e.preventDefault(); 1447 var divToPrint = document.getElementById('.article_section'); 1448 var mywindow = window.open('','','left=0,top=0,width=950,height=600,toolbar=0,scrollbars=0,status=0,addressbar=0'); 1449 1450 var is_chrome = Boolean(mywindow.chrome); 1451 mywindow.document.write($( ".article_section" ).html()); 1452 mywindow.document.close(); // necessary for IE >= 10 and necessary before onload for chrome 1453 1454 if (is_chrome) { 1455 mywindow.onload = function() { // wait until all resources loaded 1456 mywindow.focus(); // necessary for IE >= 10 1457 mywindow.print(); // change window to mywindow 1458 mywindow.close();// change window to mywindow 1459 }; 1460 } 1461 else { 1462 mywindow.document.close(); // necessary for IE >= 10 1463 mywindow.focus(); // necessary for IE >= 10 1464 mywindow.print(); 1465 mywindow.close(); 1466 } 1467 1468 return true; 1469}); 1470</script>
1470 1471
1472<script type="text/javascript"> 1473 1474var loginhash = '880ea6a14ea49e853634fbdc5015a024'; 1475var main_nav_hide_flag = true; 1476var scrollTop =0; 1477var main_nav_hide_timer = ''; 1478 1479function call_main_nav_hide() 1480{ 1481 if(main_nav_hide_flag && scrollTop >=100) 1482 { 1483 $('header').addClass("nav-up"); 1484 } 1485} 1486var cz_header_pos = $('header').offset().top; 1487$(window).scroll(function() { 1488 $('header').each(function(){ 1489 var cz_top_of_window = $(window).scrollTop()-100; 1490 if (cz_top_of_window > cz_header_pos) { 1491 $('.bc_goto_top').fadeIn("slow"); 1492 } else { 1493 $('.bc_goto_top').fadeOut("slow"); 1494 } 1495 }); 1496 1497}); 1498var prevScrollTop = 0; 1499$(window).scroll(function(event){ 1500 scrollTop = $(this).scrollTop(); 1501 1502 if ( scrollTop < 0 ) { 1503 scrollTop = 0; 1504 } 1505 if ( scrollTop > $('body').height() - $(window).height() ) { 1506 scrollTop = $('body').height() - $(window).height(); 1507 } 1508 1509 if (scrollTop >= prevScrollTop && scrollTop) { 1510 $('header').addClass("nav-up"); 1511 } else { 1512 if (scrollTop >=100) 1513 { 1514 $('header').removeClass("nav-up"); 1515 main_nav_hide_timer = setTimeout("call_main_nav_hide()",5000); 1516 } 1517 else 1518 { 1519 $('header').removeClass("nav-up"); 1520 clearInterval(main_nav_hide_timer); 1521 } 1522 } 1523 1524 prevScrollTop = scrollTop; 1525}); 1526$(document).ready(function(){ 1527 var bLazy = new Blazy(); 1528 1529 $(".bc_dropdown a").mouseenter(function(e) { 1530 $(this).parent('.bc_dropdown').delay(250).queue(function(){ 1531 $(this).addClass('show_menu').dequeue(); 1532 bLazy.revalidate(); 1533 }); 1534 main_nav_hide_flag = false; 1535 }); 1536 $(".bc_dropdown").mouseleave(function(e) { 1537 $(".bc_dropdown").clearQueue().stop().removeClass('show_menu'); 1538 main_nav_hide_flag = true; 1539 if (scrollTop >=100) 1540 { 1541 main_nav_hide_timer = setTimeout("call_main_nav_hide()",5000); 1542 } 1543 }); 1544 $('.bc_dropdown a').each(function(){ 1545 if($(this).is(":hover")) 1546 { 1547 $(this).mouseenter(); 1548 } 1549 }); 1550$('#bc_drop_tab a').hover(function (e) { 1551 e.preventDefault() 1552 $(this).tab('show') 1553 bLazy.revalidate(); 1554}); 1555 1556 $('#more_dd').click(function (e) { 1557 e.preventDefault() 1558 }); 1559 1560 $('.bc_goto_top a').click(function(){ 1561 $("html, body").animate({ scrollTop: 0 }, 600); 1562 return false; 1563 }); 1564 jQuery('.bc_login_btn').on('click', function() { 1565 jQuery('.bc_popup').fadeIn("slow"); 1566 $('#ips_username').focus(); 1567 }); 1568 jQuery('.bc_popup_close').on('click', function() { 1569 jQuery('.bc_popup').fadeOut("slow"); 1570 }); 1571 1572}); 1573 1574$(document).mouseup(function (e) 1575{ 1576 var container = $(".bc_login_form"); 1577 1578 if (!container.is(e.target) // if the target of the click isn't the container... 1579 && container.has(e.target).length === 0 && $('.bc_popup').css('display') =='block') // ... nor a descendant of the container 1580 { 1581 jQuery('.bc_popup').fadeOut("slow"); 1582 } 1583}); 1584if($(window).width() < 767) 1585{ 1586 $(".nav-menu").on('click','li', function(){ 1587 $(this).toggleClass('active').siblings().removeClass('active'); 1588 1589 }) 1590} 1591</script>
1591 1592 1593<section class="cz-popup"> 1594 <div class="cz-popup-wrapp"> 1595 <a class="cz-popup-close" href="javascript:;" title="Close"> <i aria-hidden="true" title="Times reported" class="fa fa-times"></i> </a> 1596 <h4>Reporter</h4> 1597 <div class="cz-popup-inner-wrapp"> 1598 <h6>Help us understand the problem. What is going on with this comment?</h6> 1599 <form> 1600 <input type="hidden" id="comment-id-report" value="0"> 1601 <ul> 1602 <li> 1603 <label><input type="radio" name="comment-report-reason" value="Spam">Spam</label> 1604 </li> 1605 <li> 1606 <label><input type="radio" name="comment-report-reason" value="Abusive or Harmful">Abusive or Harmful</label> 1607 </li> 1608 <li> 1609 <label><input type="radio" name="comment-report-reason" value="Inappropriate content">Inappropriate content</label> 1610 </li> 1611 <li> 1612 <label><input type="radio" name="comment-report-reason" value="Strong language">Strong language</label> 1613 </li> 1614 <li> 1615 <label><input type="radio" name="comment-report-reason" value="Other">Other</label> 1616 </li> 1617 <li id="comment-report-other-reason-wrap" style="display:none;"> 1618 <textarea aria-label="Enter other reason for reporting the comment" rows="2" cols="2" id="comment-report-other-reason"></textarea> 1619 </li> 1620 </ul> 1621 <p>Read our <a href="https://www.bleepingcomputer.com/posting-guidelines/">posting guidelinese</a> to learn what content is prohibited.</p> 1622 </form> 1623 </div> 1624 <div class="cz-popup-bottom-wrapp"> 1625 <div class="cz-popup-report-submiting" style="display:none;">Submitting...</div> 1626 <a href="#" title="Submit" class="cz-next-btn comment-report-submit-btn">SUBMIT</a> 1627 </div> 1628 </div> 1629</section> 1630 1631 <noscript id="deferred-styles"> 1632 1633<link rel="stylesheet" href="https://www.bleepstatic.com/js/redesign/fancybox/jquery.fancybox.css" type="text/css" media="screen" /> 1634 <link href="https://www.bleepstatic.com/redesign/fontawesome6/css/fontawesome.min.css" rel="stylesheet" type="text/css" media="all"> 1635 <link href="https://www.bleepstatic.com/redesign/fontawesome6/css/brands.min.css" rel="stylesheet" type="text/css" media="all"> 1636 <link href="https://www.bleepstatic.com/redesign/fontawesome6/css/solid.min.css" rel="stylesheet" type="text/css" media="all"> 1637 </noscript> 1638
1638<script> 1639 var loadDeferredStyles = function() { 1640 var addStylesNode = document.getElementById("deferred-styles"); 1641 var replacement = document.createElement("div"); 1642 replacement.innerHTML = addStylesNode.textContent; 1643 document.body.appendChild(replacement) 1644 addStylesNode.parentElement.removeChild(addStylesNode); 1645 }; 1646 var raf = requestAnimationFrame || mozRequestAnimationFrame || 1647 webkitRequestAnimationFrame || msRequestAnimationFrame; 1648 if (raf) raf(function() { window.setTimeout(loadDeferredStyles, 0); }); 1649 else window.addEventListener('load', loadDeferredStyles); 1650 </script>
1650 1651 1652 1653</body> 1654</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.