threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login alerts. Two distinct campaigns, UNK_pyreq2323 and UNK_OutFlareAZ, have been observed leveraging this tec… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel Paved With Intent: ROADtools and Nation-State Tactics in the Cloud This report details the use of ROADtools, an open-source toolkit primarily designed for red-teaming and research, by nation-state threat actors in cloud intrusions. The tool leverages legitimate Microsoft APIs to enumera… Palo Alto Unit 42 · May 22, 2026 High USentraidazureadtoken management