This Week In Security: Poking Holes In Two Factor Authentication
ID: 11bad21f-d0d6-5da5-87d8-e88963ee964d
STIX ID: report--11bad21f-d0d6-5da5-87d8-e88963ee964d
Feed Name: Security Ledger
Threat Score
### Executive Summary DUO Security disclosed a flaw in PayPal's mobile APIs that could allow an attacker with a valid PayPal username and password to bypass two-factor authentication for accounts that had 2FA enabled; PayPal temporarily disabled mobile 2FA while the issue was remediated. The report focuses on the vulnerability discovery and mitigation steps rather than evidence of active abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
