Azure Active Directory — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 28, 2025
Last Seen
July 20, 2026

Azure Active Directory is a technology platform tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 28, 2025; most recent activity July 20, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • MITRE ATT&CK T1199 — attack.mitre.org · July 20, 2026
  • Microsoft makes passkeys the default in Entra ID — Heise.De · July 14, 2026
  • Cybercriminals exploit OAuth client ID spoofing to bypass cloud security | brief — Scworld · July 13, 2026
  • Novel OAuth Client ID Spoofing Technique Targets Cloud Environments — Infosecurity-Magazine · July 13, 2026
  • Zach Hanley explains — horizon3.ai · June 15, 2026
  • Equixly API Incidents — equixly.com · June 10, 2026
  • Disruption targets Tycoon 2FA, popular AiTM PhaaS — Proofpoint · March 5, 2026
  • Inside the Rise of AI-Driven Phishing Attacks Against Microsoft 365 — Linkedin · December 30, 2025

CVSS v3.1 Breakdown