threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA systems like VPNs and Microsoft 365, and is particularly effective when combined with social engineeri… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing