Dettaglio notizia
| Data | 13/07/2026 |
| Titolo | OAuth Client ID Spoofing Enables Stealthy Microsoft Entra Account Enumeration |
| Contesto | Proofpoint reported that attackers are increasingly abusing OAuth client ID spoofing against Microsoft Entra ID to enumerate accounts and validate credentials without registering a legitimate OAuth application. The activity relies on Resource Owner Password Credentials (ROPC) authentication requests that use spoofed or random clientid values, allowing attackers to distinguish invalid usernames, valid usernames with incorrect passwords, and in some cases valid username-password pairs based on Microsoft Entra AADSTS error responses.Proofpoint said it observed at least two large-scale campaigns, UNKpyreq2323 and UNK_OutFlareAZ, using different infrastructure, user agents, and client ID generation patterns, indicating the technique is being adopted by multiple threat actors. Microsoft’s published Entra error code behavior helps explain how responses such as AADSTS700016 can leak authentication state, and defenders were urged to review Entra sign-in logs for blank or missing application names or IDs and to treat some apparent failed logins as possible signs of successful credential validation by an attacker. |
| Fonte | https://mallory.ai/stories/019f5abb-4b51-7c60-87e6-1a798468d7f8 |
| Discussione? | Parliamone sul Forum |