logo

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

ID: bf993db2-5bd2-5850-9d43-d1f7579fa1d1

STIX ID: report--bf993db2-5bd2-5850-9d43-d1f7579fa1d1

Feed Name: TrustedSec blog

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-05-01

...
...

**Executive summary:** Nyxgeek documents four distinct Azure Entra ID sign-in log bypasses (GraphNinja, GraphGhost, GraphGoblin, and a long User-Agent exploit) that enable password validation or full token issuance without generating sign-in logs; the report includes PoCs, screenshots, detection KQL for identifying missing sign-in records via Graph activity, a disclosure timeline, and commentary on Microsoft’s remediation and bounty handling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.