Security researchers have found a critical vulnerability in Microsoft Entra ID which could have allowed threat actors to gain ...
A critical combination of legacy components could have allowed complete access to the Microsoft Entra ID tenant of every ...
July 17, 2025; CVSS 10.0 Entra ID bug via legacy Graph enabled cross-tenant impersonation risking tenant compromise.
Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and ...
Microsoft recently patched a critical security vulnerability in its Entra ID system. The flaw, tracked as CVE-2025-55241, could have been exploited to take control of any ...
Until Microsoft lobbed it into a virtual volcano A security researcher claims to have found a flaw that could have handed him ...
A vulnerability that could potentially have led to the compromise of every Entra ID tenant in the world has been patched ...
Though patched, the flaw underscores systemic risks in cloud identity systems where legacy APIs and invisible delegation ...
"Since the Azure AD Graph API is an older API for managing the core Azure AD / Entra ID service, access to this API could ...
Microsoft has announced that it will automatically enable stricter secure default settings known as 'security defaults' on all existing Azure Active Directory (Azure AD) tenants in late June 2022.
Microsoft has launched Azure Service Groups in public preview, a new feature designed to simplify resource management and ...