$ techbeacon▋
CVE & Exploits

Critical Auth Bypass Lets Attackers Masquerade as 95 Employees Without Passwords or MFA

Critical Auth Bypass Lets Attackers Masquerade as 95 Employees Without Passwords or MFA

Security researchers have identified a severe authentication flaw that allowed the impersonation of 95 employee accounts, including those with elevated privileges, without requiring passwords, multi‑factor authentication or valid Microsoft Entra ID tokens.

The vulnerability originates from two separate weaknesses in a custom authentication component of the organization’s internal application. One defect bypassed token validation checks, while the second permitted the creation of forged session identifiers, together enabling a malicious actor to present themselves as any user in the directory.

Because the compromised accounts spanned ordinary staff and privileged administrators, the breach could have granted access to sensitive internal systems, confidential data repositories, and configuration tools. While the investigators have not disclosed evidence of data exfiltration, the potential for unauthorized actions remains high until remediation is complete.

Following the public disclosure by the GBHackers group, the affected company released an emergency patch to close the flawed code paths, forced password resets for all accounts, and required re‑enrollment in multi‑factor authentication. A dedicated incident‑response team has been tasked with reviewing logs, assessing any lateral movement, and notifying any impacted parties as required by regulatory guidelines.

The episode underscores a broader industry challenge: even robust identity platforms such as Microsoft Entra ID can be undermined by custom integrations that fail to uphold strict verification standards. When developers introduce bespoke authentication logic, they may unintentionally create attack surfaces that bypass the very controls meant to protect user identities.

Experts recommend that organizations conduct regular code audits of any home‑grown authentication modules, adopt zero‑trust principles that assume compromise, and implement continuous monitoring for anomalous sign‑in behavior. As the investigation proceeds, further patches and hardening measures are expected to reinforce the security posture of the affected environment and to serve as a cautionary example for other enterprises relying on custom identity solutions.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related