logo

Novel OAuth Client ID Spoofing Technique Targets Cloud Environments

ID: 45884158-fb2c-551f-9f66-eb5c5b97b38a

STIX ID: report--45884158-fb2c-551f-9f66-eb5c5b97b38a

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-13

Date Updated: 2026-07-16

...
...

Proofpoint researchers warn that attackers are spoofing OAuth client IDs in Microsoft Entra ID (formerly Azure AD) by issuing ROPC token requests that produce AADSTS error codes, allowing them to infer valid credentials and bypass Entra sign-in log detection and conditional access controls. The report states multiple large-scale campaigns are using the technique against millions of accounts across thousands of tenants and recommends treating sign-ins with blank application IDs or AADSTS700016 errors as potential indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.