❌

Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Separate Graph PowerShell apps can now enforce team-level access

Separate Graph PowerShell apps can now enforce team-level access
Microsoft Graph PowerShell administrators can give different teams tailored interactive access by creating separate Entra app registrations instead of relying on the broadly permissioned default client. The approach is especially timely as Microsoft moves delegated sessions toward Web Account Manager authentication: each app can limit both who may sign in and which Graph permissions are available after authentication.

Source

Passkey lures hide a slow Microsoft 365 data-theft campaign

Passkey lures hide a slow Microsoft 365 data-theft campaign
Microsoft is warning that attackers are using fake passkey and SSO updates to compromise Microsoft 365 identities, then quietly map tenants and collect files and email for hours or days. The campaign, active since May 2026, combines help-desk impersonation, device-code or adversary-in-the-middle phishing, unauthorized MFA enrollment, and automated Microsoft Graph activity.

Source

Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement

Entra ID passkeys become default in 2026 as SMS and voice authentication near retirement
Entra ID administrators have two deadlines to prepare for: passkeys will become the default sign-in method beginning September 1, 2026, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Organizations should identify affected users now and move them to phishing-resistant authentication before phone-based sign-ins stop working.

Source

1 in 8 credentials in public MCP files are hardcoded secrets

1 in 8 credentials in public MCP files are hardcoded secrets
Hardcoded MCP credentials are exposing AI coding agents’ connections to GitHub, databases, Slack, Notion, and other services. Hush Security’s analysis of about 82,000 public GitHub configuration files found that 12% of credential slots contained literal secrets, while more than half were difficult for conventional scanners to recognize.

Source

Cisco ISE CVSS 10 zero-day is under active attack

Cisco ISE CVSS 10 zero-day is under active attack
Cisco is urging immediate patching for a CVSS 10.0 authentication-bypass zero-day in Identity Services Engine (ISE) and ISE-PIC after confirming that attackers are exploiting it in the wild. CVE-2026-76460 can let unauthenticated remote attackers reach the web management interface through a vulnerable API, with no workaround available.

Source

Microsoft Entra Private Access offers a phased path beyond VPNs

Microsoft Entra Private Access offers a phased path beyond VPNs
Microsoft is outlining a practical route for replacing traditional VPN access with Microsoft Entra Private Access, using identity, device health, and application-level policies instead of broad network tunnels. The phased approach starts with discovering VPN-dependent resources and ends with incremental decommissioning, helping administrators modernize remote access without disrupting critical applications.

Source

❌