Visualização normal

Antes de ontemStream principal

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

31 de Agosto de 2026, 07:00

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836

24 de Agosto de 2026, 04:33

CVE-2026-69836, Entra ID, Microsoft

Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20, then quietly reversed the advisory's exploitation status a day later - leaving enterprise defenders without a clear account of whether the flaw was ever used in attacks.

The vulnerability, tracked as CVE-2026-69836, carries a CVSS score of 10.0, the highest possible rating. It stems from unsafe deserialization of untrusted data, a class of defect catalogued as CWE-502, in which an application reconstructs objects from attacker-supplied input without validating it first. Microsoft's advisory said the weakness "allows an unauthorized attacker to execute code over a network." No authentication, elevated privileges or user interaction were required.

Entra ID, formerly Azure Active Directory, is the authentication layer for Microsoft 365, Azure and thousands of federated third-party applications. Code execution inside that service sits upstream of nearly every access decision an affected tenant makes, which is why identity infrastructure flaws draw scrutiny disproportionate to their raw CVE count.

Because Entra ID is a hosted service rather than on-premises software, Microsoft was able to remediate it server-side. The company said the issue is fully mitigated and that customers need take no additional action - an unusual advantage of cloud delivery, and one that removes the patch-deployment race that normally follows a perfect-10 disclosure. Microsoft credited principal security engineer Robert Fitzpatrick with finding the bug.

"Exploited: Yes"...Sorry "No"

The disclosure itself became the story. Microsoft's Security Response Center bulletin initially carried an "Exploited: Yes" designation, prompting coverage on August 21 describing the flaw as under active attack.

Read our earlier coverage: Microsoft Says CVSS 10.0 Entra ID Code Execution Flaw Was Exploited Before Server-Side Fix

Microsoft flipped that field to "No" the same day, for reasons unknown, and offered no explanation for the change. In a follow-up statement the company said it had identified and fixed the issue and published the CVE for greater transparency.

The reversal leaves several questions open. Microsoft has not said how it detected the flaw, whether any tenant data was accessed, over what period the service was vulnerable, or what evidence supported either exploitation determination.

The episode intersects with a live regulatory question. The Securities and Exchange Commission's cyber disclosure rules require public companies to report material incidents on Form 8-K, and the Cybersecurity and Infrastructure Security Agency's reporting regime is still being finalized. Neither framework clearly addresses how a downstream customer should assess materiality when the only party holding the facts is the cloud provider.

The CVE was itself issued under MSRC's June 2024 policy of publishing CVEs for cloud service vulnerabilities that require no customer action - a transparency commitment made in the wake of criticism over the 2023 Storm-0558 intrusion. This episode is an early test of how much visibility that policy actually delivers.

Also read: Microsoft Security Lapse Exposed Sensitive Credentials and Internal Resources of Employees

Microsoft Says CVSS 10.0 Entra ID Code Execution Flaw Was Exploited Before Server-Side Fix

21 de Agosto de 2026, 11:28

Severity gauge at CVSS 10.0 beside a cloud icon, representing the maximum-severity Entra ID remote code execution flaw.

Microsoft disclosed on Thursday that a maximum-severity remote code execution vulnerability in Entra ID, the identity service underpinning Microsoft 365, Azure and Dynamics 365, was exploited in the wild before the company mitigated it on its own infrastructure. The flaw, tracked as CVE-2026-69836 and rated CVSS 10.0, required no authentication and no user interaction.

Entra ID, formerly Azure Active Directory, is the authentication and authorization layer for a large share of the world's enterprise cloud estates. It brokers sign-ins, conditional access decisions and token issuance across tenants, which makes any unauthenticated code execution in the service unusually consequential: an attacker operating inside that trust boundary is positioned upstream of nearly every control that depends on it.

According to Microsoft's advisory, the vulnerability stems from deserialization of untrusted data, a class of bug in which an application reconstructs attacker-controlled input into live objects without adequate validation. The result, per the advisory language, is that an unauthorized attacker can execute code over a network. Microsoft rated impact as high across confidentiality, integrity and availability, and characterized attack complexity as low. Credit for finding and reporting the issue went to a Microsoft principal security engineer.

Also read: Microsoft Entra ID Exposed: Actor Token Flaw Enables Stealthy Global Admin Takeover

Because Entra ID is a managed cloud service rather than software customers install, remediation happened server-side. Microsoft said the vulnerability has been fully mitigated and that there is no action for users of the service to take. Exploit code is not publicly available, the company said. Microsoft addressed several other maximum-severity cloud service issues, including flaws in Azure Arc and Exchange Online, in the same batch of disclosures.

What Microsoft did not say is drawing scrutiny. The advisory confirms exploitation but omits attribution, the window during which attacks occurred, how many tenants were touched, what attackers did after gaining execution, and any indicators defenders could use to check their own logs. Security teams face a structural problem here. With no patch to apply and no IOCs published, there is no independent way to confirm whether a given tenant was affected, and cloud-side telemetry that would answer the question sits with the provider.

The disclosure lands against a compliance backdrop that has grown less forgiving. Microsoft began issuing CVEs for cloud service vulnerabilities that require no customer action as part of transparency commitments made under its Secure Future Initiative, and CVE-2026-69836 is a test of how much that transparency actually delivers.

For U.S. public companies, exploitation of an identity provider raises Item 1.05 materiality questions under the Securities and Exchange Commission's cyber disclosure rule even when the fix is the vendor's determining whether a reportable incident occurred is difficult without provider-side evidence. In the European Union, operators in NIS2 scope carry 24-hour early-warning obligations that presuppose visibility they may not have.

Whether Microsoft publishes exploitation details or indicators, whether CISA issues supplemental guidance for federal tenants, and whether any organization ties confirmed intrusion activity to the flaw, enterprises should review Entra ID sign-in and audit logs for anomalous service principal activity, unexpected token issuance and privilege changes across the past several weeks, and re-examine standing assumptions about the identity layer.

  • ✇Cybersecurity News
  • CVE-2026-69836 (CVSS 10): Entra ID Remote Code Execution Flaw Exploited in the Wild Do Son
    CVE-2026-69836 is a CVSS 10 Entra ID remote code execution flaw exploited in the wild. Microsoft has fully mitigated it server-side. Related Posts: RDK-B WebUI Vulnerabilities Let Attackers Bypass Login CVE-2026-18963: Unauthenticated Account Takeover Flaw Hits Keycloak CVE-2026-67567 (CVSS 9.9): Red Hat Flaws Enable Privilege Escalation in ACM and FreeIPA The post CVE-2026-69836 (CVSS 10): Entra ID Remote Code Execution Flaw Exploited in the Wild appeared first on Daily CyberSecurity.
     

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

15 de Julho de 2026, 15:38

New Jalisco and OmegaLord phishing kits target Microsoft 365 accounts by abusing device code flows, OAuth tokens, and MFA prompts to maintain access.

The post Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts appeared first on TechRepublic.

Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap

6 de Julho de 2026, 13:48

A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled.

The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared first on TechRepublic.

❌
❌