Person
Dirk-jan Mollema
- First Reported
- Sep 23, 2026
- Latest Reported
- Sep 23, 2026
Reported Context (1)
- His x33fcon 2025 talk demonstrated that a rogue registered external authentication provider could bypass MFA by returning a signed JWT without a real authentication check; the researchers built on that trust boundary. TrustSink Uses a Rogue Entra Authentication Provider to Steal Passwords
MITRE ATT&CK (3)
Vendors (1)
Products (3)
Tools (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.