Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
ID: 45884158-fb2c-551f-9f66-eb5c5b97b38a
STIX ID: report--45884158-fb2c-551f-9f66-eb5c5b97b38a
Feed Name: Infosecurity Magazine (News)
Proofpoint researchers warn that attackers are spoofing OAuth client IDs in Microsoft Entra ID (formerly Azure AD) by issuing ROPC token requests that produce AADSTS error codes, allowing them to infer valid credentials and bypass Entra sign-in log detection and conditional access controls. The report states multiple large-scale campaigns are using the technique against millions of accounts across thousands of tenants and recommends treating sign-ins with blank application IDs or AADSTS700016 errors as potential indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
