logo

Meet Khaled Mohamed: the bug hunter who found a Microsoft flaw

ID: 04caffbe-ffc9-5116-933f-8a4a37d0265a

STIX ID: report--04caffbe-ffc9-5116-933f-8a4a37d0265a

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

...
...

This piece profiles researcher Khaled Mohamed and his discovery of CVE-2026-26123, a vulnerability in Microsoft Authenticator for iOS/Android that could allow a malicious app to intercept deep links or QR-code sign-in flows to steal authentication codes and bypass MFA, potentially enabling account takeover; the issue was responsibly disclosed and patched by Microsoft on 10 March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.