<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft-Entra on CuraSec</title><link>https://curasec.metacog.co.kr/tags/microsoft-entra/</link><description>Recent content in Microsoft-Entra on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/microsoft-entra/index.xml" rel="self" type="application/rss+xml"/><item><title>TheHatman Claims Mass Credential Theft from Microsoft Entra Tenants</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-threat-brief-mitigating-large-scale-credential-attacks-updat/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-threat-brief-mitigating-large-scale-credential-attacks-updat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Organizations running Microsoft Entra are directly in scope for this credential theft campaign; review MFA coverage and conditional access policies, audit Entra sign-in logs for anomalous authentication, and apply Unit 42&amp;rsquo;s hardening guidance this sprint.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> An active claimed credential-theft campaign targeting Entra tenants creates an immediate hunt requirement — sweep Entra/M365 sign-in logs for impossible travel, anomalous service principal usage, and bulk authentication failures since mid-August when the campaign surfaced.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If the organization uses Microsoft Entra, direct the security team this week to confirm whether anomalous authentication activity is present and request a status brief; prepare talking points for leadership in case credential exposure is confirmed.&lt;/li>
&lt;/ul></description></item><item><title>Kali365 Abuses Microsoft Device Code Flow to Steal OAuth Tokens</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-kali365-weaponizes-microsoft-authentication-against-us-compa/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-kali365-weaponizes-microsoft-authentication-against-us-compa/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code flow phishing is a real and growing vector for M365/Azure tenants; audit Conditional Access policies to block or restrict device code flow for user accounts that don&amp;rsquo;t require it, and enforce compliant-device requirements where the flow must remain enabled.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections on Entra ID sign-in logs for device code authorization events originating from unexpected locations or apps; also hunt for refresh token reuse anomalies that may indicate post-phishing lateral movement within M365.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A named actor targeting US M365 tenants via Microsoft&amp;rsquo;s own authentication UI is useful context for the risk register and customer security questionnaire responses, but no confirmed breaches or near-term regulatory deadlines make this a monitor-and-track item rather than an executive action.&lt;/li>
&lt;/ul></description></item><item><title>OAuth Client ID Spoofing Bypasses Entra ID Sign-In Telemetry</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-oauth-client-id-spoofing-lets-attackers-validate-stolen-micr/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-oauth-client-id-spoofing-lets-attackers-validate-stolen-micr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> At least two active threat actors are exploiting this Entra ID gap, but there&amp;rsquo;s no patch—the exposure is architectural. Audit your Entra OAuth app registrations and conditional access policies, and restrict which OAuth clients are permitted for interactive and non-interactive flows.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> This technique deliberately suppresses successful sign-in events, creating a blind spot in standard Entra telemetry; shift detection to Entra audit logs for anomalous OAuth client IDs and non-standard token-request patterns, and run a retrospective hunt across the past 90 days of OAuth activity.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Credential-validation activity against your Entra tenant may be occurring without triggering existing alerts; ask your security team to assess current detection coverage for OAuth-based evasion and confirm whether identity monitoring logs are capturing the necessary audit events.&lt;/li>
&lt;/ul></description></item></channel></rss>