CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6532

As cited

Copy frozen at (site build).

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Microsoft is discontinuing SMS multifactor authentication (MFA) for personal accounts. GitHub experienced a breach through a compromised Visual Studio Code extension. CISA will now accept researcher submissions for new known exploited vulnerabilities (KEV) entries.

Why it matters: Microsoft account users relying on SMS MFA must switch to authenticator apps or security keys to maintain account protection; GitHub users need to audit extensions and credentials for compromise; security researchers can now contribute directly to the KEV catalog, improving vulnerability tracking.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Microsoft is discontinuing SMS multifactor authentication (MFA) for personal accounts. GitHub experienced a breach through a compromised Visual Studio Code extension. CISA will now accept researcher submissions for new known exploited vulnerabilities (KEV) entries.

Why it matters: Microsoft account users relying on SMS MFA must switch to authenticator apps or security keys to maintain account protection; GitHub users need to audit extensions and credentials for compromise; security researchers can now contribute directly to the KEV catalog, improving vulnerability tracking.

VendorsMicrosoftGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary