[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhX48HFcl5o6ocr2W5lihOaTL3gIwv4610egV7-TV4S8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"57e80271-9654-42c4-bca3-2fa2296807f6","legacy-mfa-fails-against-real-time-phishing-attacks","bf5b2335-6c9c-4a3b-afc5-8557a07b15c8","Legacy MFA Fails Against Real-Time Phishing Attacks","The Figure breach exposed a critical weakness in traditional multi-factor authentication methods when attackers use real-time phishing relays (AiTM attacks). Legacy MFA solutions like push notifications, SMS codes, and TOTP authenticate the credential exchange rather than verifying the actual user identity, making them vulnerable to sophisticated social engineering. When attackers already have initial access or stolen credentials, MFA becomes just another barrier that can be bypassed through human manipulation under adversary-controlled conditions. This highlights the need for more robust authentication methods that don't rely solely on human decision-making during the authentication process.","**Immediate actions:**\n- Deploy phishing-resistant MFA methods like FIDO2\u002FWebAuthn hardware tokens\n- Implement conditional access policies that consider device trust and location context\n- Establish strict verification procedures for help desk authentication requests\n\n**Long-term improvements:**\n- Transition away from SMS and push-notification based MFA to certificate-based authentication\n- Deploy User and Entity Behavior Analytics (UEBA) to detect anomalous authentication patterns\n- Implement zero-trust architecture with continuous authentication and authorization\n\n**Detection measures:**\n- Monitor for simultaneous login attempts from geographically distant locations\n- Set up alerts for unusual help desk requests involving credential resets or MFA changes\n- Track and analyze authentication failure patterns to identify potential AiTM attacks",[12,13,14,15,16],"CIS Control 6","NIST SP 800-63B","NIST AC-2","NIST IA-2","ITIL Change Management","published","2026-04-09T19:09:03.292992+00:00","2026-04-09T19:09:02.895+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fwhen-attackers-already-have-the-keys-mfa-is-just-another-door-to-open\u002F","when-attackers-already-have-the-keys-mfa-is-just-another-door-to-open-73d243","When attackers already have the keys, MFA is just another door to open",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]