Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Constructing {custom} mannequin supplier for Strands Brokers with LLMs hosted on SageMaker AI endpoints

    March 7, 2026

    Pricing Choices and Practical Scope

    March 7, 2026

    Hackers Unfold Pretend Purple Alert Rocket Alert App to Spy on Israeli Customers

    March 7, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Entra ID vulnerability exposes gaps in cloud identification belief fashions, specialists warn
    AI Ethics & Regulation

    Entra ID vulnerability exposes gaps in cloud identification belief fashions, specialists warn

    Declan MurphyBy Declan MurphySeptember 21, 2025No Comments1 Min Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Entra ID vulnerability exposes gaps in cloud identification belief fashions, specialists warn
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    Safety researchers are warning a couple of max-severity vulnerability in Microsoft Entra ID (previously Azure Energetic Listing) that might doubtlessly enable attackers to impersonate any person in any tenant, together with International Directors, with out triggering MFA, conditional Entry, or leaving any regular login or audit path.

    The flaw, first reported by red-teamer Dirk-jan Mollema, exploited “Actor tokens,” a hidden Microsoft mechanism usually used for inner delegation, by manipulating a legacy API that didn’t validate the originating tenant.

    Based on Mitiga’s additional breakdown of the exploit, an attacker in a benign atmosphere might request an Actor token, then use it to pose as a privileged person in a very separate group.

    “The vulnerability arose as a result of the legacy API didn’t validate the tenant supply of the Actor token,” Mitiga researchers mentioned in a weblog submit. “As soon as impersonating a International Admin, they might create new accounts, grant themselves permissions, or exfiltrate delicate information.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Hackers Unfold Pretend Purple Alert Rocket Alert App to Spy on Israeli Customers

    March 7, 2026

    Clear Tribe Makes use of AI to Mass-Produce Malware Implants in Marketing campaign Concentrating on India

    March 7, 2026

    RMM Instruments Essential for IT Operations, However Rising Menace as Attackers Weaponize Them

    March 7, 2026
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Constructing {custom} mannequin supplier for Strands Brokers with LLMs hosted on SageMaker AI endpoints

    By Oliver ChambersMarch 7, 2026

    Organizations more and more deploy {custom} giant language fashions (LLMs) on Amazon SageMaker AI real-time…

    Pricing Choices and Practical Scope

    March 7, 2026

    Hackers Unfold Pretend Purple Alert Rocket Alert App to Spy on Israeli Customers

    March 7, 2026

    Motorola Razr Fold hands-on: This beats Samsung and Google Pixel in notable methods

    March 7, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.