Wednesday 12 August 2026 13:14:00 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#Entra ID


Passkeys Under Pressure: Why a Phishing-Resistant Login Can Still Become a Target

Published: 11 August 2026 10:43Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A reported attack family aimed at Windows 11 and Microsoft Entra ID is a reminder that passwordless security depends on the whole identity chain, not just the cryptography inside the key.

Windows Hello’s Quiet Shortcut: How a Live Session Can Bleed Into Cloud Identity

Published: 07 August 2026 17:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A newly disclosed Windows Hello for Business technique suggests that a user session, not a PIN, may be the real prize for attackers hunting Entra ID access.

When the Lock Screen Is Not the Finish Line

Published: 07 August 2026 16:35Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A disclosed Windows Hello for Business technique suggests that an active Windows session can become a bridge into Microsoft Entra ID, even when the attacker never learns the victim’s PIN, biometrics, or password.

Two Quiet Trust Layers, One Loud Warning: Identity Keys and NAT State Are Now in the Crosshairs

Published: 07 August 2026 12:46Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A pair of disclosures points at the same uncomfortable truth: attackers do not always need to break passwords or firewalls when they can target the long-lived state underneath them.

One Exposed Key Can Collapse a Cloud Boundary: Inside the CosmosEscape Risk

Published: 31 July 2026 12:22Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A critical flaw tied to Azure Cosmos DB shows how an account-level secret can turn a narrow mistake into broad read and write exposure.

Identity Systems Are the New Ransomware Battleground

Published: 29 July 2026 15:28Category: Ransomware & ExtortionGeo: Asia / TaiwanAuthor: HEXSENTINEL

A Foxconn ransomware case attributed to Nitrogen points to a sharper risk for defenders: identity infrastructure can become the pressure point in extortion campaigns.

When Guest Wi-Fi Becomes the Attack Surface for Cloud Identity Theft

Published: 24 July 2026 10:31Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported campaign against hotel and conference-center Wi-Fi gateways shows how DNS manipulation and risky login flows can push Microsoft 365 users toward attacker-controlled infrastructure without email lures or endpoint malware.

Fake App IDs, Real Password Tests: The Entra Trick Hiding in Plain Sight

Published: 17 July 2026 14:04Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A stealthy abuse of OAuth client IDs in Microsoft Entra ID can turn sign-in failures into an oracle for account discovery and credential checks.

When a Login Never Lands: The Quiet Identity Trick Hiding Inside Entra Telemetry

Published: 14 July 2026 16:58Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A stealthy OAuth abuse pattern is turning Microsoft Entra ID into a credential-checking tool, showing how authentication systems can leak signals even when no successful sign-in is recorded.

When Fake App IDs Become Noise: The OAuth Trick That Can Blur Entra ID Defenses

Published: 14 July 2026 16:39Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A credential attack that rotates through fictional OAuth client identities does not break encryption - it tries to break the defender’s ability to see a pattern.

Microsoft’s Entra Identity Turns Toward Passkeys, and the Fallback Problem Gets Real

Published: 14 July 2026 16:32Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft has set passkeys to become the default authentication method for Entra ID in September 2026, a change that shifts the security conversation from passwords to enrollment, recovery, and policy design.

A Beach-Themed CTF Is Teaching Defenders How Identity Attacks Hide in Plain Sight

Published: 13 July 2026 18:24Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Varonis has turned Entra ID into a training ground, showing how cloud identity investigation depends on reading logs, policy signals, and account behavior with forensic discipline.

Fake Microsoft Sign-In Pages Turn a Phone Call into an Identity Trap

Published: 10 July 2026 14:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.

The ARToken Panel Shows How Phishing Became a Token Factory

Published: 02 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.

81 Million Logins, 78 Compromises: The Password-Spray Flood Hitting Microsoft 365

Published: 02 July 2026 08:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A massive credential campaign against Microsoft 365 shows how distributed password spraying can turn identity controls into the real front line of cloud defense.

81 Million Login Shots Fired at Azure CLI - and Identity Teams Take the Hit

Published: 01 July 2026 10:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A huge password-spray wave against Microsoft’s command-line cloud tooling shows why authentication, not code, is often the real battleground in modern cloud attacks.

Agentic AI Gets an Identity Gatekeeper as Copilot Studio Moves Into the Spotlight

Published: 16 June 2026 18:25Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Aembit’s extension for Microsoft Copilot Studio highlights a growing security question: how to let AI agents act without giving them permanent credentials or unchecked reach.

When the Login Page Is Real: The Quiet Power of Device Code Phishing

Published: 16 June 2026 12:48Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing campaign aimed at Microsoft 365 users shows how attackers can abuse a legitimate OAuth flow instead of building a fake login page.

Why Microsoft Entra Logs Matter When AI Agents Start Acting Like Users

Published: 09 June 2026 14:49Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Assistive AI can move fast inside enterprise accounts, but the security story is increasingly about identity traces, delegated consent, and whether an agent’s sign-ins look normal or suspicious.

BitB Phishing Pushes Microsoft 365 Users Into a Dangerous Login Illusion

Published: 09 June 2026 14:44Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing campaign is using Browser-in-the-Browser styling to target Microsoft 365 credentials, turning ordinary sign-in habits into the attacker’s main entry point.