Weakness in Multi-Factor Authentication

I’ve been running into some interesting vulnerabilities when testing MFA implementations lately. It’s surprising how often systems fall back on less secure methods when faced with certain attack vectors. Has anyone else noticed patterns in how specific vendors handle this? Would love to compare notes on approaches for tightening security in these scenarios.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‍​​⁠​​​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠⁠‌​⁠‍‌⁠‌‍‌‍⁠‍​⁠​‌‌⁠​⁠‌⁠‌‍‌‍‍⁠‌‍‍⁠‌⁠‌‍‌‍‌‌‌​⁠⁠‌​‌​‌‌‍​‌⁠‍‌‌‍‌⁠​‍​‍‌⁠⁠‌​