Hacker News new | ask | show | jobs
by d0100 14 days ago
An employee just got phished by adding a number to a legitimate deviceAdd login route that bypasses 2FA and adds a device with full access to office and mail

Probably working as intended...

2 comments

Sounds like one of ADOs recent security misconfiguration vulnerability announcements. The customer is blamed, for not quite hardening everything the right way, when ADO config is... A sizeable task.
I always click NO to these, that's full human error. edit: The underlying issue is that they send a 2FA before asking for a password at all.