Select a theme from the list.
Insights

From our experts

Latest
OT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain DefensesCaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain DefensesCaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent Controllers
Security Insight

TrustSink Turns a Rogue MFA Provider Into a Silent Password Collector

TrustSink Turns a Rogue MFA Provider Into a Silent Password Collector
Photo by khezez | خزاز on Pexels

Researchers have demonstrated how an attacker with privileged Microsoft Entra access could register a malicious external authentication provider and capture passwords during legitimate sign-ins. The technique, called TrustSink, persists beyond individual password resets because the hostile provider remains embedded in the tenant's authentication flow until administrators remove it.

A security technique called TrustSink demonstrates how an attacker could transform a trusted multifactor authentication integration into a persistent credential collection system. The attack targets Microsoft Entra's External Authentication Methods feature, which allows organizations to use approved third-party services to complete MFA challenges.

Trust Becomes the Attack Surface

TrustSink is not an initial-access vulnerability. An intruder must first compromise an account with powerful administrative permissions, such as Global Administrator or Authentication Policy Administrator. The attacker can then register a rogue external MFA provider and assign it to selected users.

During a normal sign-in, Entra redirects the user to the external provider for the second authentication step. Instead of requesting a legitimate factor, the malicious provider displays a convincing copy of Microsoft's password page. If the user enters the password again, the credential is delivered to the attacker's server. The provider then returns a signed token claiming that MFA succeeded, allowing the login to continue without an obvious error.

The persistence is particularly concerning. Resetting a stolen password does not remove the malicious provider. The replacement password can simply be captured during the user's next authentication attempt.

What Administrators Should Review

  • Audit all external authentication methods and confirm that every provider is authorized.
  • Monitor changes to authentication policies, enterprise applications, service principals and consent grants.
  • Reduce standing access for Global Administrator and Authentication Policy Administrator accounts.
  • Require just-in-time elevation and phishing-resistant authentication for privileged identities.
  • Remove suspicious providers, applications, keys and redirect addresses before resetting passwords.

Organizations should also preserve audit records if unauthorized authentication changes are discovered. Investigators need to determine which users were assigned to the provider and whether credentials were collected during successful sign-ins.

An Identity Supply Chain Problem

In my view, TrustSink exposes a broader weakness in identity architecture. Authentication platforms increasingly depend on external providers, applications and signed assertions. Each integration becomes part of an identity supply chain whose configuration deserves the same scrutiny as privileged code.

Phishing-resistant factors remain important, but they cannot compensate for an attacker who controls the tenant's authentication policy. The defensive priority must therefore include continuous monitoring of the systems that decide which authentication methods are trusted in the first place.

Talk to our team →

Latest

OT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITSep 23, 2026Bifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionSep 23, 2026TrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorSep 23, 2026Colorado Water Attacks Show How Small Utilities Become Physical TargetsSep 22, 2026Jade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersSep 22, 2026Stolen Ribon App Credentials Open BigCommerce Stores to Data TheftSep 22, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path