A reported attack family aimed at Windows 11 and Microsoft Entra ID is a reminder that passwordless security depends on the whole identity chain, not just the cryptography inside the key.
A newly disclosed Windows Hello for Business technique suggests that a user session, not a PIN, may be the real prize for attackers hunting Entra ID access.
A disclosed Windows Hello for Business technique suggests that an active Windows session can become a bridge into Microsoft Entra ID, even when the attacker never learns the victim’s PIN, biometrics, or password.
A pair of disclosures points at the same uncomfortable truth: attackers do not always need to break passwords or firewalls when they can target the long-lived state underneath them.
A critical flaw tied to Azure Cosmos DB shows how an account-level secret can turn a narrow mistake into broad read and write exposure.
A Foxconn ransomware case attributed to Nitrogen points to a sharper risk for defenders: identity infrastructure can become the pressure point in extortion campaigns.
A reported campaign against hotel and conference-center Wi-Fi gateways shows how DNS manipulation and risky login flows can push Microsoft 365 users toward attacker-controlled infrastructure without email lures or endpoint malware.
A stealthy abuse of OAuth client IDs in Microsoft Entra ID can turn sign-in failures into an oracle for account discovery and credential checks.
A stealthy OAuth abuse pattern is turning Microsoft Entra ID into a credential-checking tool, showing how authentication systems can leak signals even when no successful sign-in is recorded.
A credential attack that rotates through fictional OAuth client identities does not break encryption - it tries to break the defender’s ability to see a pattern.
Microsoft has set passkeys to become the default authentication method for Entra ID in September 2026, a change that shifts the security conversation from passwords to enrollment, recovery, and policy design.
Varonis has turned Entra ID into a training ground, showing how cloud identity investigation depends on reading logs, policy signals, and account behavior with forensic discipline.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.
A massive credential campaign against Microsoft 365 shows how distributed password spraying can turn identity controls into the real front line of cloud defense.
A huge password-spray wave against Microsoft’s command-line cloud tooling shows why authentication, not code, is often the real battleground in modern cloud attacks.
Aembit’s extension for Microsoft Copilot Studio highlights a growing security question: how to let AI agents act without giving them permanent credentials or unchecked reach.
A phishing campaign aimed at Microsoft 365 users shows how attackers can abuse a legitimate OAuth flow instead of building a fake login page.
Assistive AI can move fast inside enterprise accounts, but the security story is increasingly about identity traces, delegated consent, and whether an agent’s sign-ins look normal or suspicious.
A phishing campaign is using Browser-in-the-Browser styling to target Microsoft 365 credentials, turning ordinary sign-in habits into the attacker’s main entry point.