<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Identity-and-Access on CuraSec</title><link>https://curasec.metacog.co.kr/tags/identity-and-access/</link><description>Recent content in Identity-and-Access on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 10 Sep 2026 14:58:06 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/identity-and-access/index.xml" rel="self" type="application/rss+xml"/><item><title>Passkey-themed social engineering enables M365 identity and cloud compromise</title><link>https://curasec.metacog.co.kr/insights/2026-09-10-passkey-themed-social-engineering-leads-to-identity-and-clou/</link><pubDate>Thu, 10 Sep 2026 14:58:06 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-10-passkey-themed-social-engineering-leads-to-identity-and-clou/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> No exploitation-pressure signals, but the MFA persistence and Microsoft Graph abuse techniques described warrant auditing Entra ID registered authentication methods for unexpected passkey enrollments and reviewing conditional access policies governing Graph API access this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> The article documents TTPs mappable to ATT&amp;amp;CK — MFA persistence registration and Microsoft Graph reconnaissance — against a near-universal enterprise target (M365); implement or tune detections for anomalous Graph API enumeration calls and unexpected MFA method additions, and hunt for such activity since early September 2026.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Passkey rollout communications are now a social engineering attack surface; if your organization is mid-deployment, review user-facing passkey enrollment messaging for impersonation risk and include this TTP in the next security-awareness training update.&lt;/li>
&lt;/ul></description></item></channel></rss>