Entra ID is a technology platform tracked across 24 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity July 20, 2026.
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
A contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) left a public GitHub repository named 'Private-CISA' exposed for six months, containing sensitive credentials including AWS GovCloud…
In a recent cybersecurity incident, attackers exploited an exposed Spring Boot Actuator endpoint to harvest credentials from leaked configuration data. They utilized the OAuth2 Resource Owner Password Credentials (ROPC)…
Token Security researcher Ariel Simon will present findings on a remote code execution (RCE) vulnerability in Microsoft’s Azure Model Context Protocol (MCP) server at the RSAC™ 2026 Conference. This flaw allows…
Microsoft has announced that starting September 1, 2026, passkeys will become the default authentication method for Entra ID, replacing SMS and voice-based multifactor authentication. This change is aimed at enhancing…
Changing passwords is a common response to suspected breaches in Active Directory (AD) environments, but it does not always eliminate the threat. Attackers can exploit cached password hashes, which may remain valid even…
Grafana Labs has issued critical patches for a severe vulnerability, CVE-2025-41115, affecting Grafana Enterprise versions 12.0.0 to 12.2.1. The flaw in the SCIM provisioning feature could enable attackers to escalate…