TrustSink Uses a Rogue Entra Authentication Provider to Steal Passwords
Varonis researchers demonstrate TrustSink, a technique that uses a rogue Entra external authentication provider to capture plaintext passwords during sign-in and return a valid token, keeping the trap active even after password resets.
