22:42
2026-08-05
cloudsecurityalliance.org
ai-safety
The Ghost Applications: How OAuth Client ID Spoofing Enumerates Microsoft Entra Accounts Without a Successful Sign-In
Proofpoint's threat research team reported that attackers exploited OAuth client ID spoofing to enumerate Microsoft Entra ID accounts without successful sign-ins, with two campaigns using fabricated aโฆ