Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
OAuth Consent Abuse: Why MFA Isn't Enough — Detection and Remediation Guide for Entra ID
Introduction Multi-factor authentication has become the default answer to identity attacks — and for password-based credential theft, it rem...
ShinyHunters Passkey Phishing Campaign Targets Microsoft 365: Detection and Defense Guide for SSO Social Engineering Attacks
Introduction Microsoft has confirmed that threat actors affiliated with ShinyHunters, Helix, and other extortion-focused criminal groups are...
Identity Attacks Drove Half of All Confirmed Intrusions in Q2 2026: Detection and Hardening Guide for the Top 4 Attack Patterns
Introduction Between May and July 2026, Prophet Security investigated every alert across its customer environments — not a sampled subset, n...
Passkey-Themed Social Engineering: How Attackers Hijack Entra ID Identities and Pivot to Cloud Data — Detection and Hardening Guide
Introduction Microsoft's threat intelligence teams have published a critical warning this week: threat actors are running passkey-themed soc...
The MFA Identity Trap: How Attackers Pass Authentication and What Defenders Must Detect Instead
When "Authenticated" Doesn't Mean "Trusted" A hard truth is circulating through the security community, crystallized in a recent SecurityWee...
Finding the MFA Gaps: Auditing Entra ID MFA Enrollment with PowerShell and Microsoft Graph Beta (and Catching Attackers Doing the Same)
The Rollout Is Never Actually Done Every identity team that has driven a multi-factor authentication rollout knows the moment: leadership as...
CVE-2026-65801: Critical Microsoft Cloud CVEs (Exchange Online SSRF, Entra ID Deserialization, Fabric Path Traversal) — Detection and Remediation Guide
Three CVSS 10-Class Bugs in the Microsoft Identity and Collaboration Plane In the last 72 hours, NVD published three CRITICAL, network-vecto...
Storm-0501 Azure Cloud Ransomware: Detecting Tenant Hijacking, Backup Destruction, and Key Vault Encryption Abuse
Introduction The ransomware playbook has fundamentally changed, and Storm-0501 is the proof. This financially motivated threat actor — track...
Windows Hello for Business Key Abuse: Defending Against Malware-Driven Persistent Entra ID Access
Windows Hello for Business Key Abuse: Defending Against Malware-Driven Persistent Entra ID Access Introduction Entra ID security researcher ...