❌

Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 5 octobre 2026IT
Hier — 4 octobre 2026IT

Sign in to Microsoft apps with passkeys from external identity providers

Par : IT Experts
2 octobre 2026 à 22:54
Browser authentication hand-off and return flow (image Microsoft)
Microsoft Entra ID can now hand the sign-in step of a federated domain to the system browser on Android, iOS, and managed macOS. This browser authentication for external identity providers lets users sign in to Outlook, Teams, OneDrive, and other brokered Microsoft apps with passkeys or FIDO2 security keys issued by a third-party identity provider (IdP). The feature is off by default, works only for domains federated through WS-Fed or SAML 2.0, and requires a broker app on the device. You enable it per platform with Microsoft Graph or Microsoft Graph PowerShell. This article explains how it works, what you need, and where the documentation is unclear.

Source

Exchange throttling and Entra’s shift from AD spotlight Microsoft’s IT changes

Par : IT News
2 octobre 2026 à 22:53
Microsoft is tightening email handling for outdated Exchange servers while Entra takes on more of Active Directory’s role. The changes sit alongside Microsoft-AWS multicloud efforts and planned improvements to Windows Search, highlighting a broad shift in enterprise IT management.

Source

À partir d’avant-hierIT

Microsoft 365 for IT Pros October update adds safer Graph permissions

Par : IT News
1 octobre 2026 à 16:54
Microsoft 365 for IT Pros October update adds safer Graph permissions
Microsoft 365 for IT Pros’ October 2026 update highlights new, lower-privilege Microsoft Graph permissions for Entra ID groups and clarifies key Microsoft 365 changes. SMS-based MFA remains scheduled to end on February 1, 2027, with a four-month extension for global administrators and external users.

Source

Microsoft starts locking down Entra ID sign-ins against script injection

Par : IT News
30 septembre 2026 à 21:30
Microsoft starts locking down Entra ID sign-ins against script injection
Microsoft will begin enforcing tighter Content Security Policy checks on Entra ID sign-ins in mid-October 2026, blocking externally injected scripts and limiting logon pages to trusted Microsoft CDN content. The change rolls out automatically, needs no tenant configuration, and is meant to reduce exposure to cross-site scripting and other sign-in attacks.

Source

AI’s Third Wave: Persistent AI agents

Par : IT News
30 septembre 2026 à 21:30
AI's Third Wave: Persistent AI agents
Truly persistent AI coworkers are forcing a new security model: unlike today’s task-scoped agents, they are expected to keep credentials, accumulate access, and operate with standing privileges much like human employees. That shift builds on the problems seen in rogue AI agents, but the new risk is that the identity itself now becomes persistent, not just the action.

Source

Pentagon database flaw exposed Social Security numbers of more than 3 million people

Par : IT News
29 septembre 2026 à 22:38
Pentagon database flaw exposed Social Security numbers of more than 3 million people
A flaw in a Defense Manpower Data Center file-sharing system exposed Social Security numbers and other personal data tied to more than 3 million people with U.S. military connections. The breach stretched from October 2025 until July 16, 2026, and the Pentagon says there is no sign the information has been misused.

Source

Okta’s Blueprint Alliance sets a cross-vendor path to govern AI agents

Par : IT News
29 septembre 2026 à 14:29
Okta’s Blueprint Alliance sets a cross-vendor path to govern AI agents
Okta has formed a cross-vendor alliance to coordinate how organizations discover and control AI agents, with new detection and policy-enforcement tools due later this year. The rollout includes shadow-agent detection in the third quarter and expanded runtime kill-switch capabilities in the fourth.

Source

Palo Alto brings Prisma AIRS security to NVIDIA’s agent platform

Par : IT News
29 septembre 2026 à 14:14
Palo Alto brings Prisma AIRS security to NVIDIA’s agent platform
Palo Alto Networks is adding gateway, runtime, and identity controls to NVIDIA’s Open Agent Safety Platform, which launched with OpenShell and Sentry to limit what AI agents can do. The rollout has different timelines: Prisma AIRS AI Runtime Security is generally available on NVIDIA BlueField DPUs, while the gateway’s Vera CPU deployment is future-facing and the IDIRA integration is planned.

Source

Storm-3168 used two Azure service principals to destroy cloud resources

Par : IT News
28 septembre 2026 à 16:48
Storm-3168 used two Azure service principals to destroy cloud resources
Storm-3168, also known as JADEPUFFER, used two compromised Azure service principals to map a tenant and rapidly destroy cloud resources in an 18-hour campaign. Most storage accounts targeted were deleted, but resource locks and deletion protection blocked some attacks and prevented wider damage.

Source

Self-service onboarding for new Microsoft Entra App Gallery applications

Par : IT Experts
25 septembre 2026 à 23:21
Publish to Entra App Gallery (image Microsoft)
Microsoft has released a public preview of self-service onboarding for new applications to the Microsoft Entra App Gallery. The App Gallery is a catalog of thousands of SaaS (software as a service) applications that are preintegrated with Microsoft Entra ID, so you can add them to your tenant and configure single sign-on (SSO) and automated user provisioning with minimal effort. The new experience targets independent software vendors (ISVs) that want to list their applications in the gallery. As an administrator, you benefit indirectly: more validated applications should become available faster, because publishers can now catch configuration problems before Microsoft reviews their submissions. Microsoft announced the preview on September 17, 2026.

Source

Separate Graph PowerShell apps can now enforce team-level access

Par : IT News
24 septembre 2026 à 11:53
Separate Graph PowerShell apps can now enforce team-level access
Microsoft Graph PowerShell administrators can give different teams tailored interactive access by creating separate Entra app registrations instead of relying on the broadly permissioned default client. The approach is especially timely as Microsoft moves delegated sessions toward Web Account Manager authentication: each app can limit both who may sign in and which Graph permissions are available after authentication.

Source

Microsoft takedown exposes EvilTokens AI-powered fraud service behind 12,000 inbox breaches

Par : IT News
23 septembre 2026 à 18:22
Microsoft takedown exposes EvilTokens AI-powered fraud service behind 12,000 inbox breaches
Microsoft and its partners have dismantled EvilTokens, an AI-powered cybercrime service linked to more than 12,000 compromised email inboxes across over 10,000 organizations. The operation seized 50 websites, disabled more than 150 supporting domains, and led to the arrest of two men in the UK.

Source

Passkey lures hide a slow Microsoft 365 data-theft campaign

Par : IT News
22 septembre 2026 à 10:56
Passkey lures hide a slow Microsoft 365 data-theft campaign
Microsoft is warning that attackers are using fake passkey and SSO updates to compromise Microsoft 365 identities, then quietly map tenants and collect files and email for hours or days. The campaign, active since May 2026, combines help-desk impersonation, device-code or adversary-in-the-middle phishing, unauthorized MFA enrollment, and automated Microsoft Graph activity.

Source

Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement

Par : IT News
21 septembre 2026 à 16:52
Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement
Entra ID administrators have two deadlines to prepare for: passkeys will become the default sign-in method beginning September 1, 2026, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Organizations should identify affected users now and move them to phishing-resistant authentication before phone-based sign-ins stop working.

Source

1 in 8 credentials in public MCP files are hardcoded secrets

Par : IT News
18 septembre 2026 à 10:56
1 in 8 credentials in public MCP files are hardcoded secrets
Hardcoded MCP credentials are exposing AI coding agents’ connections to GitHub, databases, Slack, Notion, and other services. Hush Security’s analysis of about 82,000 public GitHub configuration files found that 12% of credential slots contained literal secrets, while more than half were difficult for conventional scanners to recognize.

Source

Cisco ISE CVSS 10 zero-day is under active attack

Par : IT News
17 septembre 2026 à 11:55
Cisco ISE CVSS 10 zero-day is under active attack
Cisco is urging immediate patching for a CVSS 10.0 authentication-bypass zero-day in Identity Services Engine (ISE) and ISE-PIC after confirming that attackers are exploiting it in the wild. CVE-2026-76460 can let unauthenticated remote attackers reach the web management interface through a vulnerable API, with no workaround available.

Source

❌
❌