An Accenture researcher discovered a vulnerability in Windows Hello for Business (WHfB) that allows downgrade attacks, enabling threat actors to bypass even biometric protections. Using the Evilginx adversary-in-the-middle attack framework, attackers can intercept and alter authentication requests, downgrading WHfB to less

5m read timeFrom darkreading.com
Post cover image
Table of contents
Authentication Downgrades With Adversary-in-the-MiddleWHfB's Phishing-Resistant ModelMicrosoft's Remediation: New Conditional Access Policy

Sort: