❌

Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Sign in to Microsoft apps with passkeys from external identity providers

Browser authentication hand-off and return flow (image Microsoft)
Microsoft Entra ID can now hand the sign-in step of a federated domain to the system browser on Android, iOS, and managed macOS. This browser authentication for external identity providers lets users sign in to Outlook, Teams, OneDrive, and other brokered Microsoft apps with passkeys or FIDO2 security keys issued by a third-party identity provider (IdP). The feature is off by default, works only for domains federated through WS-Fed or SAML 2.0, and requires a broker app on the device. You enable it per platform with Microsoft Graph or Microsoft Graph PowerShell. This article explains how it works, what you need, and where the documentation is unclear.

Source

Microsoft starts locking down Entra ID sign-ins against script injection

Microsoft starts locking down Entra ID sign-ins against script injection
Microsoft will begin enforcing tighter Content Security Policy checks on Entra ID sign-ins in mid-October 2026, blocking externally injected scripts and limiting logon pages to trusted Microsoft CDN content. The change rolls out automatically, needs no tenant configuration, and is meant to reduce exposure to cross-site scripting and other sign-in attacks.

Source

AI’s Third Wave: Persistent AI agents

AI's Third Wave: Persistent AI agents
Truly persistent AI coworkers are forcing a new security model: unlike today’s task-scoped agents, they are expected to keep credentials, accumulate access, and operate with standing privileges much like human employees. That shift builds on the problems seen in rogue AI agents, but the new risk is that the identity itself now becomes persistent, not just the action.

Source

Palo Alto brings Prisma AIRS security to NVIDIA’s agent platform

Palo Alto brings Prisma AIRS security to NVIDIA’s agent platform
Palo Alto Networks is adding gateway, runtime, and identity controls to NVIDIA’s Open Agent Safety Platform, which launched with OpenShell and Sentry to limit what AI agents can do. The rollout has different timelines: Prisma AIRS AI Runtime Security is generally available on NVIDIA BlueField DPUs, while the gateway’s Vera CPU deployment is future-facing and the IDIRA integration is planned.

Source

Self-service onboarding for new Microsoft Entra App Gallery applications

Publish to Entra App Gallery (image Microsoft)
Microsoft has released a public preview of self-service onboarding for new applications to the Microsoft Entra App Gallery. The App Gallery is a catalog of thousands of SaaS (software as a service) applications that are preintegrated with Microsoft Entra ID, so you can add them to your tenant and configure single sign-on (SSO) and automated user provisioning with minimal effort. The new experience targets independent software vendors (ISVs) that want to list their applications in the gallery. As an administrator, you benefit indirectly: more validated applications should become available faster, because publishers can now catch configuration problems before Microsoft reviews their submissions. Microsoft announced the preview on September 17, 2026.

Source

Separate Graph PowerShell apps can now enforce team-level access

Separate Graph PowerShell apps can now enforce team-level access
Microsoft Graph PowerShell administrators can give different teams tailored interactive access by creating separate Entra app registrations instead of relying on the broadly permissioned default client. The approach is especially timely as Microsoft moves delegated sessions toward Web Account Manager authentication: each app can limit both who may sign in and which Graph permissions are available after authentication.

Source

Passkey lures hide a slow Microsoft 365 data-theft campaign

Passkey lures hide a slow Microsoft 365 data-theft campaign
Microsoft is warning that attackers are using fake passkey and SSO updates to compromise Microsoft 365 identities, then quietly map tenants and collect files and email for hours or days. The campaign, active since May 2026, combines help-desk impersonation, device-code or adversary-in-the-middle phishing, unauthorized MFA enrollment, and automated Microsoft Graph activity.

Source

Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement

Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement
Entra ID administrators have two deadlines to prepare for: passkeys will become the default sign-in method beginning September 1, 2026, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Organizations should identify affected users now and move them to phishing-resistant authentication before phone-based sign-ins stop working.

Source

1 in 8 credentials in public MCP files are hardcoded secrets

1 in 8 credentials in public MCP files are hardcoded secrets
Hardcoded MCP credentials are exposing AI coding agents’ connections to GitHub, databases, Slack, Notion, and other services. Hush Security’s analysis of about 82,000 public GitHub configuration files found that 12% of credential slots contained literal secrets, while more than half were difficult for conventional scanners to recognize.

Source

Cisco ISE CVSS 10 zero-day is under active attack

Cisco ISE CVSS 10 zero-day is under active attack
Cisco is urging immediate patching for a CVSS 10.0 authentication-bypass zero-day in Identity Services Engine (ISE) and ISE-PIC after confirming that attackers are exploiting it in the wild. CVE-2026-76460 can let unauthenticated remote attackers reach the web management interface through a vulnerable API, with no workaround available.

Source

❌