Microsoft has disclosed a maximum-severity remote code execution vulnerability in its cloud-based identity and access management service, Microsoft Entra ID (formerly Azure…
Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
Cybersecurity researchers have uncovered new components in the Cavern (aka Cav3rn) command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting…
Three independent research efforts presented at Black Hat USA 2026 and in subsequent disclosures have demonstrated practical attacks against passkey implementations, undermining…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
UNK_OutFlareAZ is a threat cluster that exploited OAuth client ID spoofing starting December 2025, leveraging Cloudflare infrastructure to target over 2 million…
Account EnumerationCloudflareCredential ValidationMicrosoft Entra ID
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service. It was affected by CVE-2026-69836, a critical…