Tag

#Entra ID

7 stories taggedEntra ID.

A Microsoft security patch notification dashboard showing 22 fixes rolling out across cloud services, with six critical severity indicators glowing red at maxim
Vulnerabilities

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity

A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

3 min read
Microsoft cloud infrastructure with an Entra ID vulnerability being remotely exploited, followed by a patch installation completing on the server side
Identity & Access

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed

Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

3 min read
Illustration: a dense server rack aisle in a data center
Cloud Security

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached

Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.

3 min read
Illustration: A dimly lit corporate office at night
Identity & Access

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.

Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

3 min read
Illustration: a phishing attack targeting Microsoft 365 users, showing a hacker bypassing security measures
Identity & Access

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA

The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

3 min read
Illustration: A digital montage of AI technology identifying vulnerabilities in software code
Vulnerabilities

Microsoft Skips a Zero-Day for the First Time in Two Years. Nobody Wants to Talk About Why.

118 fixes shipped, none under active exploit, and a quiet Anthropic project keeps surfacing in vendor briefings. Microsoft, Apple and Oracle declined to discuss it on the record.

3 min read
Illustration: a hacker targeting Microsoft 365 through OAuth
Identity & Access

FBI flags Kali365, the latest phishing kit pitched at draining Microsoft 365 tenants

The bureau says the subscription-priced service abuses OAuth device-code flows to lift session tokens and walk straight past MFA.

3 min read
© 2026 Threat Vectr