Where Multi-Factor Authentication Stops and Credential Abuse Starts
ID: 57633858-bcf8-5db1-a78a-07960762da37
STIX ID: report--57633858-bcf8-5db1-a78a-07960762da37
Feed Name: The Hacker News
**Executive summary:** This article details seven Windows authentication paths that can bypass cloud-enforced MFA—interactive/domain logons, direct RDP, NTLM, Kerberos ticket abuse (pass-the-ticket/Golden/Silver Ticket), reused local administrator credentials, SMB-based lateral movement, and long-lived service accounts—and recommends mitigations such as stronger AD password policies, continuous blocked/compromised-password checks, reducing legacy protocols like NTLM, auditing and rotating service accounts, and deploying controls (e.g., Specops Secure Access and Specops Password Policy) to close these authentication gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
