How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse
Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...
When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...
The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...
SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach...
Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.
The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...
ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.
SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...
The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...
Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...
Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.
The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...
AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.
Use this checklist to govern AI agent identities in your organization.
The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...
Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in...
After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.
The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...
On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had...
The tj-actions compromise showed that referencing GitHub Actions by tag lets an attacker change your pipeline without touching your code. Here is how to pin...
Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...
The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...
In March 2025, a threat actor using the name "rose87168" claimed to have stolen millions of records from Oracle Cloud's single sign-on (SSO) login...
When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...