Security News

- Previous Post >>

MU.SCL S03E06 – Catch Me If You Can: Life After MFA and Zero Trust in the Age of AI

Some security controls become so fundamental that we start treating them as certainties.
Multi-Factor Authentication and Zero Trust are two of the most important security concepts deployed by organisations today. Neither is obsolete, and both remain essential. But attackers, and technology, are changing the assumptions on which we have built them.

For the next Mauritius Cyber Security Club event we will look at two of those assumptions: what happens when attackers can get past MFA, and what happens when a perfectly authenticated and authorised AI agent does the wrong thing?

MU.SCL S03E06 – Catch Me If You Can will take place on Tuesday, 6 October 2026 6pm at the Flying Dodo in Bagatelle (Mauritius)

Talk 1 – Life After MFA
Sylvain Martinez – ElysiumSecurity


Multi-Factor Authentication has long been one of the closest things cybersecurity has had to a silver bullet:
Stealing a password was no longer enough, an attacker also needed access to another authentication factor, dramatically increasing the difficulty of compromising an account.
That remains true - but the threat has evolved.

Modern attacks increasingly target the authentication process itself rather than simply trying to steal a password: Adversary-in-the-Middle phishing can intercept an authenticated session, session tokens can be stolen and replayed, users can be manipulated into approving authentication requests, and alternative authentication flows can sometimes be abused.
In some of these attacks, the victim successfully completes MFA and the attacker still obtains access. Microsoft has documented attacks in which session cookies captured through AiTM phishing allowed attackers to impersonate users without requiring another MFA interaction.

This does not mean MFA has failed or should be abandoned, but it means that MFA can no longer be treated as the end of the identity security discussion.

This talk will look at how attackers bypass or sidestep MFA in practice, why some MFA mechanisms provide significantly stronger protection than others, and what organisations need to put around authentication to defend identities once MFA alone is no longer enough.

Talk 2 – Zero Trust: Is Zero Really Zero?
Sylvain Martinez – ElysiumSecurity


Zero Trust did not remove trust, it changed where and how trust decisions are made.
Instead of implicitly trusting a user or system because it is inside a network, Zero Trust continuously evaluates access according to policy and signals such as identity, device state, resource, environment and observed behaviour. Authentication and authorisation can therefore be continually reassessed rather than granted once and assumed indefinitely.
But Agentic AI introduces a different problem:
An AI agent may have a valid identity, it may run from an approved device or workload, ts credentials may be legitimate, its request may comply perfectly with the organisation's access policy and its action may still be wrong!

An autonomous agent can misunderstand an instruction, follow manipulated information, pursue an unintended objective or simply make a bad decision while remaining completely authenticated and authorised.
The traditional Zero Trust question is essentially:
Should this entity be allowed to perform this action under the current policy?


Agentic AI introduces another:
Should the entity be doing this at all?

That distinction matters and this talk will examine what Agentic AI means for Zero Trust architectures, where traditional authentication and authorisation controls stop, and whether security architectures designed to continuously verify who and what we trust now also need mechanisms capable of evaluating why an autonomous system is acting.

Join the discussion
MU.SCLis a free cybersecurity event open to technical and non-technical participants.
It provides an opportunity to learn, ask questions, exchange practical experience and meet members of the Mauritian cybersecurity community.

Event details
  • Date: Tuesday, 6 October 2026
  • Time: 18:00
  • Venue: Flying Dodo, Bagatelle
  • Attendance: Free
  • You can register here: EVENTBRITE

    - Previous Post >>