{"id":4619,"date":"2024-09-07T05:56:36","date_gmt":"2024-09-06T17:56:36","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/09\/07\/20240906news\/"},"modified":"2025-03-10T11:11:32","modified_gmt":"2025-03-09T22:11:32","slug":"20240906news","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/09\/07\/20240906news\/","title":{"rendered":"Identity security news &#8211; September 6"},"content":{"rendered":"\n<p>Some recent news articles of interest on identity security &#8230;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Cisco Talos on frequency of MFA attacks in 2024<\/strong><\/h4>\n\n\n\n<p>During the first quarter of 2024, Cisco Talos&#8217;s incident response teams saw MFA attacks in almost half of all security incidents they worked on, with fraudulent MFA push notifications in one quarter of attacks. <\/p>\n\n\n\n<p>Using another data set from Cisco Duo deployments, Cisco also said that many MFA push notification attacks are timed for pre-work hours (e.g., 8-9am) in the hope that distracted workers will let something slip through. <\/p>\n\n\n\n<p>See <a href=\"https:\/\/www.cybersecuritydive.com\/news\/mfa-multi-factor-authentication-cisco-talos-cyber\/719254\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cybersecurity Dive<\/a>.<br><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Design flaw in Microsoft Authenticator<\/h4>\n\n\n\n<p>Microsoft Authenticator, an app for safeguarding accounts with time-based tokens for MFA, has a long-standing design flaw that Microsoft doesn&#8217;t seem keen to fix. When a user scans a QR code to add a new account, but their user name is the same as one that already exists in the app, Authenticator will overwrite the most recent one. Oops. The user may not realize their loss until some time later, at which point they are most likely to blame the issuer of the code, not Authenticator. This flaw does not apply to Microsoft-issued codes. <\/p>\n\n\n\n<p>See <a href=\"https:\/\/www.csoonline.com\/article\/3480918\/design-flaw-has-microsoft-authenticator-overwriting-mfa-accounts-locking-users-out.html\" target=\"_blank\" rel=\"noreferrer noopener\">CSO Online<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">OTP Agency founders plead guilty to charges<\/h4>\n\n\n\n<p>The three founders of the OTP Agency in the United Kingdom, a service that enabled the theft of one-time codes used for authentication, plead guilty to charges of making and supplying articles for use in fraud and money laundering. When the OTP Agency was operational, it sold a weekly subscription for bypassing multi-factor authentication safeguards and had around 2,200 members on its Telegram group.<\/p>\n\n\n\n<p>See <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/09\/03\/10-million-2fa-bypass-hackers-promised-profit-in-minutes-on-telegram\/\" target=\"_blank\" rel=\"noreferrer noopener\">Forbes<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Identity security news: frequency of MFA attacks in 2024, design flaw in Microsoft Authenticator, and the OTP Agency for stealing one-time codes.<\/p>\n","protected":false},"author":384585,"featured_media":4484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027311],"tags":[712027529],"class_list":["post-4619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity","tag-whats-going-down"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2021\/08\/grammatech2021.jpg?fit=1160%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1cv","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4619"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4619\/revisions"}],"predecessor-version":[{"id":4645,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4619\/revisions\/4645"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4484"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}