Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 5 août 2026Flux principal

Kali365 turns Microsoft device-code logins into persistent M365 access

Par : IT News
5 août 2026 à 16:11
Kali365 turns Microsoft device-code logins into persistent M365 access
Kali365 is targeting US organizations by abusing Microsoft’s legitimate device-code authentication flow, allowing attackers to obtain Microsoft 365 OAuth tokens without stealing passwords. More than 80 public sandbox sessions tied to the phishing kit are appearing each week, highlighting a persistent threat to corporate email, documents, and cloud services.

Source

Cloudflare Identity-Aware AI Gateway puts names behind AI requests

Par : IT News
5 août 2026 à 16:11
Cloudflare Identity-Aware AI Gateway puts names behind AI requests
Cloudflare’s Identity-Aware AI Gateway now lets enterprises connect AI requests to verified employees, devices, and automated systems instead of anonymous shared API keys. The service combines identity-aware access with spending controls, anomaly detection, logging, and safeguards for prompts sent to external AI providers.

Source

Edit on-prem Exchange attributes in Exchange Online with writeback for cloud-managed remote mailboxes

Par : IT Experts
4 août 2026 à 22:19
Cloud-managed Exchange attribute architecture (image Microsoft)
Microsoft has made Exchange attribute writeback for cloud-managed remote mailboxes generally available. It lets you manage selected Exchange mailbox attributes in Exchange Online while copying a limited set of those values back to on-premises Active Directory through Microsoft Entra Cloud Sync. This article explains the prerequisites, configuration, verification, and operational limits for a hybrid Exchange organization.

Source

Greatness PhaaS adds device-code phishing to harvest MFA-backed tokens

Par : IT News
4 août 2026 à 22:00
Greatness PhaaS adds device-code phishing to harvest MFA-backed tokens
Greatness, a commercial phishing-as-a-service platform, now lets attackers combine adversary-in-the-middle theft, OAuth consent abuse, and device-code phishing from one dashboard. The new capability can obtain valid access tokens without collecting a victim’s password, turning a legitimate Microsoft sign-in into an MFA bypass.

Source

Entra Connect gets a 2026 cutoff as Microsoft urges Tier 0 treatment

Par : IT News
4 août 2026 à 19:20
Entra Connect gets a 2026 cutoff as Microsoft urges Tier 0 treatment
Microsoft Entra Connect administrators have a firm upgrade deadline: synchronization will stop on September 30, 2026, unless the service runs version 2.5.79.0 or later. The deadline adds urgency to a broader security reset: Entra Connect should be protected as Tier 0 infrastructure, not deployed like ordinary middleware.

Source

À partir d’avant-hierFlux principal

Using external fingerprint readers with Windows Hello Enhanced Sign-in Security

Par : IT Experts
3 août 2026 à 22:35
Confirm Enhanced Sign-in Security is on (image Microsoft)
Windows Hello Enhanced Sign-in Security (ESS) can now use a compatible external fingerprint reader for Windows sign-in on Windows 11, version 24H2 and 25H2. ESS is a Windows Hello protection mode that isolates biometric processing and the connection to the reader from the main operating system. This article explains the hardware and update requirements, enrollment process, verification steps, and deployment limits for Windows administrators.

Source

Malware can silently hijack Chrome’s synced passkeys on Windows

Par : IT News
3 août 2026 à 19:52
Malware can silently hijack Chrome’s synced passkeys on Windows
Malware with ordinary user privileges can bypass the protections users expect from Google Password Manager passkeys, including fingerprints, PINs, and visible prompts. Unit 42 identified three attack paths against Chrome’s Google Cloud Authenticator that can produce valid login assertions or extract synced passkey keys without breaking passkey cryptography.

Source

Migrate2GSA brings a safer Microsoft Entra Global Secure Access migration path

Par : IT News
3 août 2026 à 18:09
Migrate2GSA brings a safer Microsoft Entra Global Secure Access migration path
Microsoft Entra Global Secure Access migrations no longer have to start with rebuilding every application and policy manually. The open-source Migrate2GSA toolkit preserves existing Secure Service Edge configuration, converts it into a reviewable format, and provisions approved changes through Microsoft Graph—with safeguards designed to keep administrators in control.

Source

Microsoft’s Copilot super app will put chat, code and agents behind one door

Par : IT News
3 août 2026 à 16:37
Microsoft’s Copilot super app will put chat, code and agents behind one door
Microsoft plans to launch a unified Copilot super app that combines chat, GitHub Copilot coding assistance, Cowork collaboration, and autonomous Autopilots for consumer and commercial users. The consolidation could simplify access to Microsoft’s expanding AI lineup, but licensing, permissions, administration, and the fate of existing apps remain unsettled.

Source

Device code phishing hits industrial scale with 25+ active kits

Par : IT News
31 juillet 2026 à 15:21
Device code phishing hits industrial scale with 25+ active kits
Device code phishing has moved from a niche technique to an industrialized threat, with more than 25 active kits and new campaigns appearing rapidly. The OAuth 2.0 attack can bypass MFA and passkeys by stealing access tokens after users authenticate on legitimate identity-provider pages.

Source

Microsoft: Least privilege for AI agents needs more than narrow roles

Par : IT News
29 juillet 2026 à 21:34
Microsoft: Least privilege for AI agents needs more than narrow roles
AI agents need dedicated identities, task-scoped permissions, approved tool allowlists, and fast revocation—not broad service-account access. New guidance also emphasizes short-lived entitlements, context-aware authorization, and mandatory human approval for high-impact actions.

Source

1Password Privileged Access removes standing access for AI agents

Par : IT News
28 juillet 2026 à 18:20
1Password Privileged Access removes standing access for AI agents
1Password has launched Privileged Access, a just-in-time access control feature that gives engineers and AI agents only the permissions required for a specific task. Access is automatically removed when the session ends, reducing the risk of forgotten privileges and exposed credentials.

Source

❌
❌