The Varonis research team discovered a way to bypass multi-factor authentication for Box accounts that use authenticator apps such as Google Authenticator.
Varonis threat researcher Kody Kinzie demonstrates how an attacker could use stolen credentials to compromise an organization’s Box account and exfiltrate sensitive data without providing a one-time password.
We disclosed this issue to Box on November 3rd via HackerOne and the team has since released a fix. Read our full write-up and attack flow diagram at: https://www.varonis.com/blog/box-mfa-...
More from Varonis ⬇️
Visit our website: https://www.varonis.com
LinkedIn: / varonis
X/Twitter: / varonis
Instagram: / varonislife
#Box #VaronisThreatLabs #CYbersecurity