👀 Agents are quickly becoming part of the identity attack surface. Are you keeping an on them? We recently identified an issue where Copilot Studio didn't log key administrative modifications to agents.
Details & detections:
https://t.co/gMijtJ3lMI
@Cyb3rMonk I used to think this, but was surprised how many folks don't follow cons closely. The blog, talk 1, talk 2 will all get slightly different outreach - especially if social algorithm traction wasn't great for whatever reason. I still try & hold off at 2 max.
Seeing new attributes pop-up is a strong signal that something is brewing in Entra ID.
Ever wish this could be surfaced in an automated way?
Enter https://t.co/HlCiR9DXjn - An automated system that scrapes #Entra for changes on a daily basis.
#EntraID#infosec#mvpbuzz
This BlueHat talk from Dylan Ryan-Zilavy and Cameron Vincent (@SecretlyHidden1) is an awesome watch! Fantastic bug and explanation of overlooked OAuth 'aud' claim validation:
https://t.co/EyO58uU3nV
Malicious skills are evolving, and attackers are finding ways to execute them before model-level defenses even activate.
In the first post of our new series, I’ll show you how dynamic context in coding agents can introduce new supply chain risks:
https://t.co/xdqgUo8xEA
Launching https://t.co/Z3gUh4OCOA
Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub).
Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾
🚨 Hey!! Have you checked out Stratus Red Team lately? We've been busy adding new techniques in Azure/Entra and GCP! Full lists below:
GCP: https://t.co/XYW0QedTKa
Azure: https://t.co/hCewWFHjb1
Entra: https://t.co/IUZZBUgKFp
If you're curious to see how you can backdoor conditional access policies by using a legitimate hidden condition then have a gander here:
https://t.co/PcS4spbfCA
Datadog Security Research continues to push the boundaries of modern cloud security—including AI security!
@_sigil shares her finding on logging gaps affecting Copilot Studio, allowing adversaries to evade detection.
https://t.co/fx8KQrZe1k
🤔 Ever wondered what Microsoft Graph's batch requests are doing? I've released a Burp Suite extension to help untangle them here:
https://t.co/Ly7iHL8FsG
@stokfredrik Your energy and positivity are an inspiration to me!!
The algorithm can get bent on rage, & I'm sorry to hear some of that negativity got aimed at you. :(
Excited to see what you create whenever you're ready again, but zero rush.