Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
ID: bf993db2-5bd2-5850-9d43-d1f7579fa1d1
STIX ID: report--bf993db2-5bd2-5850-9d43-d1f7579fa1d1
Feed Name: TrustedSec blog
Threat Score
**Executive summary:** Nyxgeek documents four distinct Azure Entra ID sign-in log bypasses (GraphNinja, GraphGhost, GraphGoblin, and a long User-Agent exploit) that enable password validation or full token issuance without generating sign-in logs; the report includes PoCs, screenshots, detection KQL for identifying missing sign-in records via Graph activity, a disclosure timeline, and commentary on Microsoft’s remediation and bounty handling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
