Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Targeting RSA Emergency Access Tokencodes for Fun and Profit

Summary

Shows how an attacker with domain credentials can request an RSA Emergency Access Tokencode from the self-service console and brute force the numeric PIN, turning recovery features into a 2FA bypass.
Published
Collected

original ↗