As cited
Copy frozen at (site build).
cloud saas
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers conducting account enumeration against Microsoft cloud tenants are spoofing OAuth client IDs to evade detection in sign-in logs. By using fake identifiers in authentication requests, the attackers' probing activity avoids appearing in the normal telemetry that Microsoft Entra ID records. Microsoft and operators are working to address this detection gap.
Why it matters: Cloud administrators relying on Entra ID sign-in logs to detect unauthorized access attempts may miss account enumeration activity if attackers use spoofed OAuth client IDs, requiring review of detection rules and logging configuration today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers conducting account enumeration against Microsoft cloud tenants are spoofing OAuth client IDs to evade detection in sign-in logs. By using fake identifiers in authentication requests, the attackers' probing activity avoids appearing in the normal telemetry that Microsoft Entra ID records. Microsoft and operators are working to address this detection gap.
Why it matters: Cloud administrators relying on Entra ID sign-in logs to detect unauthorized access attempts may miss account enumeration activity if attackers use spoofed OAuth client IDs, requiring review of detection rules and logging configuration today.
- Source published
- First seen by Cybersecurity Tracker