logo

Downgrade Attack Allows Phishing Kits to Bypass FIDO

ID: e1388409-984a-50c8-9222-9e1061e65cb9

STIX ID: report--e1388409-984a-50c8-9222-9e1061e65cb9

Feed Name: Dark Reading

Threat Score
50/100

Date Published: 2025-08-14

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Proofpoint researchers demonstrated a proof-of-concept phishing downgrade attack that uses the Evilginx AitM framework to spoof a victim's user agent and force Microsoft Entra ID to fall back from FIDO to weaker MFA methods, enabling attackers to harvest credentials and session tokens; the technique could be integrated into commercial phishing kits, though no real-world instances have been observed to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.