top | item 34102639

(no title)

axsharma | 3 years ago

Probable explanation for the mysterious hacks on Xfinity accounts despite having 2FA enabled:

2FA bypass allegedly circulating privately

"A researcher has told BleepingComputer that the attacks are being conducted through credential stuffing attacks to determine the login credentials for Xfinity attacks.

Once they gain access to the account and are prompted to enter their 2FA code, the attackers allegedly use a privately circulated OTP bypass for the Xfinity site that allows them to forge successful 2FA verification requests."

discuss

order

No comments yet.