Back Feeds.4Sysops OAuth client ID spoofing allows stealthy Microsoft Entra account enumeration
Attackers are exploiting a novel technique called OAuth client ID spoofing to bypass traditional detection mechanisms in Microsoft Entra ID. By sending authentication requests with fabricated or random client identifiers, threat actors can perform account enumeration and password validation without triggering standard alerts. This method utilizes the Resource Owner Password Credentials flow to submit credentials directly to the Microsoft identity platform. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
