CuraSec

tag: Cloud-Identity · 1 items

2026-09-13 · The Hacker News · source ↗ #phishing#cloud-identity#microsoft
  • Engineer — Learn: Demonstrates that passkey-themed social engineering can bypass MFA assumptions — worth factoring into how passkey enrollment flows and conditional access policies are hardened, but no CVE or patch action follows from this disclosure.
  • SOC/IR — Plan: The active campaign pattern — CEO-impersonation lures leading to passkey/cloud credential harvesting — is worth building detections around: hunt for anomalous passkey registration events in Entra ID and tune email-gateway rules for third-party-relayed CEO impersonation at volume.
  • Leader — Learn: Useful context that passkey adoption does not eliminate cloud account takeover risk; informs future board or customer messaging about layered identity controls, but no vendor breach or regulatory trigger here.