logo

Researchers Crack Microsoft Azure MFA in an Hour

ID: 478e9812-c40e-5f69-b903-7d4aa6466e59

STIX ID: report--478e9812-c40e-5f69-b903-7d4aa6466e59

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-12-11

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Oasis Security disclosed "AuthQuake", a Microsoft Azure MFA bypass that allowed attackers to rapidly create sessions and enumerate 6‑digit TOTP codes because of absent rate limits and an extended code tolerance window; researchers showed an attacker could reach ~50% success after about 24 sessions (~70 minutes). Microsoft patched the flaw after disclosure; recommended mitigations include strict rate limiting, shorter TOTP tolerance, MFA failure alerts, and use of authenticator apps or strong passwordless methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.