Downgrade Attack Allows Phishing Kits to Bypass FIDO
ID: e1388409-984a-50c8-9222-9e1061e65cb9
STIX ID: report--e1388409-984a-50c8-9222-9e1061e65cb9
Feed Name: Dark Reading
Threat Score
Proofpoint researchers demonstrated a proof-of-concept phishing downgrade attack that uses the Evilginx AitM framework to spoof a victim's user agent and force Microsoft Entra ID to fall back from FIDO to weaker MFA methods, enabling attackers to harvest credentials and session tokens; the technique could be integrated into commercial phishing kits, though no real-world instances have been observed to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
