Microsoft corrected a public-by-default configuration and code flaws in a cloud automation service that may have created a cross-tenant identity risk, without any confirmed exploitation in the available material.
A reported campaign against hotel and conference-center Wi-Fi gateways shows how DNS manipulation and risky login flows can push Microsoft 365 users toward attacker-controlled infrastructure without email lures or endpoint malware.
A compromise at the hotel or conference network edge can steer Microsoft 365 sign-ins off course, showing how DNS tampering can become an identity attack without phishing or malware.
A new recovery option puts camera-based identity checks alongside email and phone, expanding the ways account access can be restored when normal sign-in fails.
Microsoft is working to resolve an Exchange Online issue that is mistakenly quarantining customer mailboxes, a reminder that cloud email controls can fail without any attacker in sight.
A flaw in Adobe’s Acrobat Chrome extension could let websites access WhatsApp Web content rendered in the browser, underscoring how sensitive data can surface after encryption has already done its job.
A near account takeover tied to SIM swap fraud shows why identity checks must change as risk signals change, not freeze at login.
A legitimate Microsoft sign-in path is being treated as an attack surface, where user approval can hand an adversary a valid session without breaking the protocol itself.
New standardized fields in AWS Data Exports make Bedrock spending easier to trace, compare, and govern, reducing the need for brittle billing parsers.
A reported .NET Native AOT module shifts the communication layer toward Microsoft 365 calendar objects and adds a DNS recovery path, showing how cloud identity surfaces can become part of malware plumbing.
The latest NIST digital identity guidance pushes organizations toward phishing-resistant login, ongoing risk checks, and Zero Trust thinking, but the real challenge is how to make that work across cloud, SaaS, and recovery flows.
SecurityWeek’s on-demand Cloud & Data Security Summit is a reminder that cloud risk is less about one headline threat and more about the daily choices around identity, data, and configuration.
A stealthy abuse of OAuth client IDs in Microsoft Entra ID can turn sign-in failures into an oracle for account discovery and credential checks.
A use-case guide turns into a sharper lesson: identity security tools only work when they match the way an organization actually authenticates, escalates privilege, and moves trust around.
Credential-sharing habits make password-based checkout brittle, and the shift to passkeys changes the risk model for Click to Pay without making identity security automatic.
Two disclosed authorization flaws could let a low-privilege view into OAuth material and cross-tenant broker metadata, underscoring how messaging systems depend on disciplined boundary enforcement.
A new healthcare warning puts supply-chain security, identity management, and staff readiness in the same frame: cyber risk becomes operational risk when hospitals cannot trust who connects, who updates, or who responds.
A stealthy OAuth abuse pattern is turning Microsoft Entra ID into a credential-checking tool, showing how authentication systems can leak signals even when no successful sign-in is recorded.
A quiet identity trick is turning Microsoft Entra authentication into a validation oracle, where fake client IDs and direct-password flows can help attackers learn which accounts and credentials are worth pursuing.
A credential attack that rotates through fictional OAuth client identities does not break encryption - it tries to break the defender’s ability to see a pattern.