Microsoft Entra ID is a technology platform tracked across 34 threat clusters and 43 intelligence report mentions on ThreatCluster. First observed November 27, 2025; most recent activity July 24, 2026.
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
On March 11, 2026, medical technology firm Stryker experienced a significant cyberattack attributed to the Iran-linked hacking group Handala. The attack exploited vulnerabilities in Stryker's Microsoft Intune endpoint…
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
Miggo Security discovered two critical vulnerabilities in RabbitMQ, a widely used open-source message broker. The flaws, CVE-2026-57219 and CVE-2026-57221, were present since early 2024 and allow unauthenticated…
A critical scoping vulnerability was identified in Microsoft Entra ID's Agent Identity Platform, enabling users with the Agent ID Administrator role to hijack arbitrary service principals within an organization's…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…