threat-intel
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
High
Summary
This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA systems like VPNs and Microsoft 365, and is particularly effective when combined with social engineering tactics. The Cisco breach serves as a prime example of how this technique can bypass even robust security programs, highlighting the vulnerability of push-based MFA and the need for stronger authentication methods.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
