Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel
Identity abuse is one of the clearest operational threats in the feed, especially around Microsoft 365 and Entra ID. Attackers are using fake passkey enrollment, device-code flow abuse, OAuth client ID spoofing, malicious guest accounts, and consent tricks to evade detection and harvest credentials. These techniques matter because they often generate weak telemetry or no successful sign-in event, which makes…
Read the article →Passwordless identity and MFA changes are reshaping enterprise access management
Vendors are steadily shifting away from SMS and older second factors toward passkeys and hardware-backed authentication. Microsoft announced passkeys as the default sign-in experience for Entra ID and described future deadlines for users still…
Read the article →Google and Microsoft are tightening identity and OAuth telemetry after stealthy account attacks
Attackers have started abusing OAuth client ID behavior in Microsoft Entra ID to enumerate accounts and evade normal sign-in logging. Proofpoint showed that spoofed client IDs can let operators infer whether usernames or passwords…
Read the article →



