Another idiotic thing this so-called "security" #joomla patch gets wrong is that it does not reset the MFA retry count when you log in with WebAuthn (or any other "silent" login). You know, the authentication options which deliberately bypass MFA because the security is guaranteed otherwise.