Russian Threat Actors Bypass MFA via OAuth and WhatsApp Device Pairing
New article details Russian threat actors bypassing MFA without password theft by exploiting OAuth and WhatsApp device pairing. Targets include government, defense, and academia, but technique applicable to any enterprise using OAuth or WhatsApp. Signals increased risk for organizations relying solely on MFA, potentially impacting security spending and incident response priorities.
Sources (3)
Updated Aug 22, 2026