0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies
In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...
Insights
Articles in Entra ID & Identity.
In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...
FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.
SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.
The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...
In May 2022, Microsoft announced Microsoft Entra, a new product family for identity and access. Azure Active Directory became part of Entra, and in July...
Microsoft Entra now includes many products. Here is a practical way to map them to an identity security roadmap for a mid-sized organization.
Use this checklist to assess an identity security program for a mid-sized organization.
The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...
Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including...
MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much...
MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...
The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...
Continuous Access Evaluation (CAE) changed how quickly Microsoft Entra ID can cut off access. Microsoft announced general availability in early 2022 after a...
Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and...
Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.
The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...
On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...
The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...
Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...
The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...
After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...
Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.
Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...
The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...