Security researchers have discovered a vulnerability affecting TOTP- and HOTP-based MFA implementations. The flaw makes it possible to intercept and reuse one-time codes under certain network conditions, compromising the security of millions of corporate accounts.
Vendors have already released patches, but it is estimated that tens of thousands of organizations are still running vulnerable versions. The finding has reopened the debate on the security of software-based MFA solutions versus hardware-based ones, and several experts recommend migrating to FIDO2 keys or physical tokens as an immediate preventive measure.






