Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials

Threat actors are exploiting a novel evasion technique called OAuth client ID spoofing to silently validate stolen Microsoft Entra ID credentials without generating successful sign-in logs, thereby bypassing standard authentication monitoring. This method allows attackers to enumerate valid accounts and confirm credentials without triggering alerts, creating a significant blind spot for defenders. While no specific patch is mentioned, experts recommend deploying phishing-resistant MFA, enforcing strong password policies, and adopting an assume-breach mindset to limit lateral movement.
Read Full Article →

Identity OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials July 14, 2026 Share By Steve Zurier (Adobe Stock) At least two threat actors have weaponized a novel evasion technique called OAuth client ID spoofing in multiple cloud campaigns. According to a July 13 Proofpoint blog , this new technique lets users enumerate accounts and validate stolen credentials in Microsoft Entra ID environments without ever generating a successful sign-in that would normally alert defenders. Shane Barney, CISO at Keeper Security, said by spoofing OAuth client IDs, attackers have found a way to confirm which credentials are valid inside an organization's cloud environment without leaving a trace in the logs that security teams use to catch them. Barney said cloud identity platforms only log what they recognize, and attackers are exploiting that gap at scale. That blind spot isn't a misconfiguration, said Barney, it’s a fundamental problem with how most organizations are approaching cloud identity monitoring. “Authentication logs are only as valuable as they are complete,” said Barney. “When activity goes unrecorded, security teams are operating on an incomplete picture of their environment, making decisions based on data that doesn't reflect what’s actually happening. No alert fires, no analyst investigates and the organization has no indication that its credentials have been quietly tested and confirmed. By the time those credentials surface in an active intrusion, the opportunity for early intervention has already passed.” Jason Fruge, resident CISO at XM Cyber, added that the important insight for CISOs isn't the technical details: it's the shift in assumptions. Fruge said many security teams rely on the idea that testing stolen credentials leaves a noticeable trail before an attacker gains access. This method eliminates that early warning by letting attackers quietly confirm valid credentials, then log in as if nothing unusual happened. Fruge said techniques like this keep emerging, forcing defenders to rethink the assumptions they depend on. Prevention remains critical: deploy phishing-resistant MFA wherever possible and enforce strong password practices to reduce the value of stolen credentials. But Fruge said no control is foolproof, so adopt an assume-breach mindset. “Plan for the possibility that a valid credential might get through and focus on limiting the damage,” said Fruge. “That requires closing off pathways for lateral movement like flat networks, unnecessary standing privileges, unsegmented admin access, and other related exposures." Steve Zurier Related Privacy LAPD ends contract with Flock Safety over privacy concerns SC Staff July 13, 2026 The decision by the LAPD, one of Flock's largest government clients, follows similar moves by other major U.S. cities like Mountain View, California, and South Portland, Maine, which also cited privacy worries and potential misuse of data by federal agencies. Identity Argentine Football Association systems reportedly compromised after nearly year-old infostealer infection SC Staff July 13, 2026 The breach was discovered after mass emails were sent from legitimate AFA domains, claiming Argentina "stole" the win from Egypt. Identity Inheriting trust: Why unified identity fabrics are becoming essential for agentic AI Paul Wagenseil July 13, 2026 Your outmoded identity-management system isn't built to handle AI agents. Here's what you need to know. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article