Microsoft
Curated coverage and analysis in this editorial area.

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID
Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…

Why an Active Directory Password Reset Isn't Enough to Evict an Attacker
A simple Active Directory password reset often fails to eliminate persistence. Valid Kerberos tickets, local hash caching, and ACL-bas…

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign
Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

Microsoft Zero-day: The Risk of the Faulty Patch Revealed
Discover the impact of the faulty Microsoft patch that left a new zero-click backdoor in Windows Shell. What to know about CVE-2026-32…