OAuth 클라이언트 ID 스푸핑이 MS Entra ID에서 공격자를 위협한다.
최소 두 개의 서로 다른 위협 행위자들이 OAuth 클라이언트 ID 스푸핑이라는 새로운 회피 기법을 활용하고 있습니다. 이 기법은 사용자가 Microsoft Entra ID 환경에서 사용자 계정을 나열하고 도난당한 자격 증명을 검증할 수 있도록 합니다. 심지어 성공적인 로그인 이벤트를 생성하지 않아 방어자들을 경고하지 않게 됩니다. 이러한 공격은 클라우드 캠페인에서 이루어지고 있습니다.
OAuth client ID spoofing threatens attackers in Microsoft Entra ID.
At least two distinct threat actors are using a novel evasion technique called OAuth client ID spoofing. This technique allows users to enumerate accounts and validate stolen credentials in Microsoft Entra ID environments without generating a successful sign-in event that would alert defenders. This type of attack is being deployed in cloud campaigns.