Baldwin Consulting Services, LLC

Continuity Management and Technology Services – News Reblog

SolarWinds hackers have a clever way to bypass multi-factor authentication | Ars Technica

During one of the intrusions, Volexity researchers noticed the hackers using a novel technique to bypass MFA protections provided by Duo. After having gained administrator privileges on the infected network, the hackers used those unfettered rights to steal a Duo secret known as an akey from a server running Outlook Web App, which enterprises use to provide account authentication for various network services.

Article Link