An infostealer log can bypass MFA—respond within the first hour
A corporate password found in an infostealer log should be treated as a possible live identity compromise, not just an old credential leak. Security teams need to determine within minutes whether the data includes active browser sessions, identity-provider access, VPN or RDP credentials, and then revoke sessions and reset passwords before attackers can use them.
Source
👉@sysadminoff
https://4sysops.com/archives/an-infostealer-log-can-bypass-mfa-respond-within-the-first-hour/
Post #19849
58
