CuraSec

Act active

Passkey-themed social engineering enables M365 identity and cloud compromise

2026-09-10 14:58 UTC · Microsoft Security Blog · read the source ↗ #social-engineering#identity-and-access#cloud-security
  • Engineer — Plan: No exploitation-pressure signals, but the MFA persistence and Microsoft Graph abuse techniques described warrant auditing Entra ID registered authentication methods for unexpected passkey enrollments and reviewing conditional access policies governing Graph API access this quarter.
  • SOC/IR — Act: The article documents TTPs mappable to ATT&CK — MFA persistence registration and Microsoft Graph reconnaissance — against a near-universal enterprise target (M365); implement or tune detections for anomalous Graph API enumeration calls and unexpected MFA method additions, and hunt for such activity since early September 2026.
  • Leader — Plan: Passkey rollout communications are now a social engineering attack surface; if your organization is mid-deployment, review user-facing passkey enrollment messaging for impersonation risk and include this TTP in the next security-awareness training update.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.