Meet Khaled Mohamed: the bug hunter who found a Microsoft flaw
ID: 04caffbe-ffc9-5116-933f-8a4a37d0265a
STIX ID: report--04caffbe-ffc9-5116-933f-8a4a37d0265a
Feed Name: Malwarebytes Blog
Threat Score
This piece profiles researcher Khaled Mohamed and his discovery of CVE-2026-26123, a vulnerability in Microsoft Authenticator for iOS/Android that could allow a malicious app to intercept deep links or QR-code sign-in flows to steal authentication codes and bypass MFA, potentially enabling account takeover; the issue was responsibly disclosed and patched by Microsoft on 10 March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
