Threat Brief — 2026-09-22 — Rogue MFA, npm impostor, regulatory fallout
Executive summary
Three genuinely new items emerged in the last few hours. The most technically significant is a demonstrated attack where a privileged adversary registers a rogue external MFA provider that transparently captures users' passwords during legitimate authentication flows. Separately, a malicious npm package disguised as a Twilio bug-bounty probe is targeting developers and exfiltrating credentials. On the regulatory side, Sweden's privacy regulator fined IT provider Miljödata $183,000 for security failures that exposed 2.2 million people. Microsoft also pushed informational acknowledgement updates for six previously disclosed CVEs—no new patches or severity changes.
Top items
- Rogue external MFA provider can intercept passwords during legitimate logins. Researchers demonstrated that an attacker with privileged tenant access can register an untrusted external MFA provider that captures users' passwords as they authenticate normally. The attack abuses legitimate federation/extension mechanisms rather than a software vulnerability, making it difficult to detect with standard signature-based tooling. The prerequisite is privileged access to the identity provider's configuration, which limits opportunistic use but makes it a potent post-compromise persistence technique. (src: BleepingComputer)
- Malicious npm package "tw-pkgprobe-7731" masquerades as Twilio security tool. The package presents itself as a bug-bounty probe targeting developers integrating Twilio, while silently harvesting credentials. Developers who install it as part of a Twilio integration workflow are the intended victims. This is the latest in a sustained wave of npm supply-chain attacks that exploit trust in familiar vendor names. (src: The Hacker News)
- Sweden fines Miljödata $183,000 for breach affecting 2.2 million people. Sweden's data protection authority (IMY) penalised IT systems provider Miljödata for inadequate security measures that led to an August 2025 breach. The fine and the affected population size underscore regulators' increasing willingness to hold service providers directly accountable for systemic security failures, not just data controllers. (src: BleepingComputer)
- Microsoft updates acknowledgements for six previously disclosed CVEs. Six Microsoft CVEs received informational acknowledgement updates only—no new patches, severity changes, or exploit-status revisions. The affected components are Windows DHCP Server (CVE-2026-69620 RCE, CVE-2026-77886 DoS), Windows File History Service (CVE-2026-57091 EoP), Win32k (CVE-2026-69498 EoP), SMB Client (CVE-2026-69572 information disclosure), and ASP.NET Core (CVE-2026-57099 DoS). (src: MSRC CVE-2026-69620, MSRC CVE-2026-57091, MSRC CVE-2026-69498, MSRC CVE-2026-69572, MSRC CVE-2026-77886, MSRC CVE-2026-57099)
Themes
Identity infrastructure as attack surface. The rogue MFA provider research fits a broader pattern this cycle—multiple stories (EvilTokens phishing-as-a-service, Keycloak password-reset takeover, browser-extension AI-assistant hijacking) all target authentication and identity layers rather than traditional endpoint or network vulnerabilities. Attackers are increasingly operating within legitimate identity workflows rather than bypassing them.
Supply-chain impostors continue to exploit developer trust. The tw-pkgprobe-7731 package is the latest in a long run of npm attacks that mimic well-known vendors (TanStack, LastPass, Twilio). The common thread is packaging malicious code inside names and contexts that developers would instinctively trust during integration work.
