Gbhackers Critical Bypass of Azure AD Conditional Access Discovered
Article Content
- •Howler Cell's red team engagement demonstrated a bypass of Azure AD Conditional Access.
- •The attack method involves phantom device registration and PRT abuse.
- •No patch or mitigation strategy has been released by Microsoft as of now.
An authorized red team operation by Howler Cell has revealed a method to bypass Microsoft Entra ID (formerly Azure AD) Conditional Access. This security feature is crucial for cloud identity management, enforcing access based on user location, device compliance, and risk scores. The attack exploits phantom device registration and PRT abuse, allowing unauthorized access to systems that rely on this security. The full scope of affected organizations is currently unknown, but the implications for cloud security are significant. Microsoft has not yet released a patch or mitigation strategy for this vulnerability. Security teams are advised to review their Conditional Access configurations and monitor for suspicious activities. The attack highlights the need for enhanced security measures in cloud identity systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Howler Cell and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…