Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Could This 5M Investment Be The Pinocchio Moment For Quantum Computing?

Could This $375M Investment Be The Pinocchio Moment For Quantum Computing?

11 June 2026
The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says

The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says

11 June 2026
The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

11 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Google And Microsoft Users Warned As New 2FA Bypass Attacks Reported
Innovation

Google And Microsoft Users Warned As New 2FA Bypass Attacks Reported

Press RoomBy Press Room26 December 20245 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Google And Microsoft Users Warned As New 2FA Bypass Attacks Reported

Update, Dec. 25, 2024: This story, originally published Dec. 23 now includes details of another 2FA bypass threat, AuthQuake, that has been fixed but serves as another warning to the dangers of thinking of two-factor authentication as being a security silver bullet.

Security researchers have warned that the demise of the Rockstar 2FA exploit service isn’t all good news—far from it, as here comes FlowerStorm, which could be the same threat that’s evolved. What Google and Microsoft users need to know.

The Demise Of Rockstar 2FA And The Rise Of FlowerStorm 2FA Bypass Attacks—What Google And Microsoft Users Need To Know

Regular readers will no doubt recall the warning regarding a two-factor authentication bypass exploit attack service called Rockstar 2FA, not least as that warning came less than a month ago. Based on telemetry gathered by Sophos researchers,” the security outfit said, “it appears that the group running the service experienced at least a partial collapse of its infrastructure, with pages associated with the service no longer reachable.” This, the researchers were quick to point out, was not apparently down to law enforcement takedown action as is often the case. You might think, therefore, that reports of the death of Rockstar 2FA were a good thing. I’m not so sure, and nor is Sophos it would seem.

So, while it’s not bad news that some of that Rockstar 2FA infrastructure, such as Telegram channels used for command and control or pages that return a HTTP 522 response currently, a connection timed out error specific to Cloudflare, that another threat has filled the void most certainly is. That new threat comes by way of something called FlowerStorm, and there are some strong signs that it might not be as new as it seems.

The FlowerStorm 2FA Bypass Threat Explained

In a Dec. 19 report, the principal threat researcher at Sophos X-Ops, Sean Gallagher, and Mark Parsons, a threat hunter for Sophos Managed Detection and Response, warned that “in the weeks following the disruption of Rockstar2FA, we observed a surge in the use of a similar set of PaaS portals that have been tagged by some researchers as “FlowerStorm”—the name coming from the use of plant-related terms in the HTML page titles of many of the phishing pages themselves.” Interestingly, the FlowerStorm phishing-as-a-service resource shares a number of features with Rockstar, according to Sophos. The FlowerStorm 2FA exploit platform has been active since at least June, 2024, according to Sophos, but has a “significant number of similarities to Rockstar2FA,” including the format of its phishing portal pages and the connection to its backend server.

Mitigating The FlowerStorm 2FA Bypass Threat

Google and Microsoft users are advised to be alert for any signs of phishing as this is how most 2FA bypass attacks, inlcuding this one, begin. See what Paul Walsh of MetaCert has to say about that here, but meanwhile a Google spokesperson said there are “numerous protections to combat such attacks, including passkeys, which substantially reduce the impact of phishing and other social engineering attacks.” Such security keys are known to be a stronger protection against “automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication,” according Google.

2FA Systems Based On Shared Secrets Are Inherently Vulnerable, Security Experts Warn

According to a recent analysis from researchers based at Oasis Security, a critical vulnerability in Microsoft’s 2FA implementation could have enabled attackers to bypass this additional layer of authentication protection and gain unauthorized access to users’ Office 365 Microsoft accounts. Here’s what you need to know about the AuthQuake vulnerability.

AuthQuake relied upon one worryingly simple vulnerability, as is often the case with such things, namely that there was a relatively easy way to get around the 10-attempt code fail rate limit meant to prevent an attacker from executing multiple, simultaneous, 2FA code entry attempts. Given a side-digit 2FA code, the AuthQuake vulnerability could have enabled an attacker to quickly work through the options and crack the code. As I reported at the time, the Oasis researchers both identified and successfully demonstrated the 2FA bypass, “which required no user interaction, generated no alerts and could be executed in under 70 minutes with a 50% success rate.”

Oasis reported the flaw to Microsoft, and a fix was deployed on Oct. 9, although the full details of that fix remain confidential. “We appreciate the partnership with Oasis security in responsibly disclosing this issue. We have already released an update, and no customer action is required,” a Microsoft spokesperson said.

AuthQuake exposed significant flaws in Microsoft’s 2FA implementation, according to Jason Soroko, a senior fellow at Sectigo, which provides certificate lifecycle management services. “Authentication systems based on shared secrets are inherently vulnerable,” Soroko said, “this discovery is a wake-up call. Organizations must act to adopt patches and reconsider their reliance on outdated MFA solutions. We must strive toward passwordless authentication solutions…”

2FA attack 2FA security FlowerStorm Google 2FA attack MFA attack Microsoft 2FA attack Microsoft 365 attack Rockstar 2FA Sophos two factor authentication attack
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Could This 5M Investment Be The Pinocchio Moment For Quantum Computing?

Could This $375M Investment Be The Pinocchio Moment For Quantum Computing?

11 June 2026
The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

11 June 2026
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 2026
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 20262 Views
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 20264 Views
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 20262 Views
Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, M Microsoft deal

Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal

11 June 20262 Views

Recent Posts

  • Could This $375M Investment Be The Pinocchio Moment For Quantum Computing?
  • The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says
  • The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus
  • Meta is tackling the blue-collar worker shortage by investing $115 million in data center trade jobs
  • Humana To Divest End-Of-Life Care Business For $900 Million

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Could This 5M Investment Be The Pinocchio Moment For Quantum Computing?

Could This $375M Investment Be The Pinocchio Moment For Quantum Computing?

11 June 2026
The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says

The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says

11 June 2026
The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

The World Cup’s Real Viral Threats Aren’t Ebola Or Hantavirus

11 June 2026
Most Popular
Meta is tackling the blue-collar worker shortage by investing 5 million in data center trade jobs

Meta is tackling the blue-collar worker shortage by investing $115 million in data center trade jobs

11 June 20262 Views
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 20262 Views
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 20264 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.