A critical vulnerability in Microsoft’s Multi-Factor Authentication (MFA) implementation has been uncovered by Oasis Security’s research team, potentially exposing over 400 million Office 365 accounts to unauthorized access.
The flaw, dubbed “AuthQuake,” allowed attackers to bypass MFA protections and gain access to user accounts, including Outlook emails, OneDrive files, Teams chats, and Azure Cloud resources.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
The AuthQuake flaw stemmed from two key issues in Microsoft’s MFA system:
These vulnerabilities allowed malicious actors to potentially breach MFA defenses within 70 minutes, achieving a success rate exceeding 50%. Alarmingly, the exploit required no user interaction and generated no alerts, leaving account holders oblivious to the ongoing attack.
The bypass technique exploited weaknesses in the time-based one-time password (TOTP) system:
Upon notification by Oasis Security, Microsoft took swift action:
The permanent fix involved introducing stricter rate-limiting mechanisms that activate after a number of failed attempts, lasting for approximately half a day.
While this specific vulnerability has been addressed, the incident highlights the importance of robust MFA implementations. Security experts recommend:
Despite this setback, MFA remains a critical security measure. Organizations are advised to continue using MFA, preferably with authenticator apps or stronger passwordless methods while staying vigilant against potential vulnerabilities.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…
According to IBM Security annual research, "Cost of a Data Breach Report 2024", an average…
A critical security flaw in NVIDIA's Riva framework, an AI-powered speech and translation service, has…
CISA officially added a significant security flaw affecting Broadcom’s Brocade Fabric OS to its authoritative…
A critical vulnerability in Apple’s AirPlay protocol, dubbed AirBorne, has exposed over 2.35 billion active…
A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to…