
8/8/2023 · Jensen Stava
What this post added
Introduced a new security measure for non-2FA users requiring email verification during login for high-risk attempts to mitigate credential stuffing attacks. This involves prompting users to enter a code sent to their email. A one-time option to update their email address is provided during this verification process.