Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
The Hacker News
4 weeks ago

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

By info@thehackernews.com (The Hacker News)

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begun

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.