Researchers Crack Microsoft Azure MFA in an Hour
ID: 478e9812-c40e-5f69-b903-7d4aa6466e59
STIX ID: report--478e9812-c40e-5f69-b903-7d4aa6466e59
Feed Name: Dark Reading
Date Published: 2024-12-11
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Oasis Security disclosed "AuthQuake", a Microsoft Azure MFA bypass that allowed attackers to rapidly create sessions and enumerate 6‑digit TOTP codes because of absent rate limits and an extended code tolerance window; researchers showed an attacker could reach ~50% success after about 24 sessions (~70 minutes). Microsoft patched the flaw after disclosure; recommended mitigations include strict rate limiting, shorter TOTP tolerance, MFA failure alerts, and use of authenticator apps or strong passwordless methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
