SECURITY·중요도 9·2026. 07. 14.·The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
── KO ──────────────────
OAuth 클라이언트 ID 스푸핑이 MS Entra ID에서 공격자를 위협한다.
최소 두 개의 서로 다른 위협 행위자들이 OAuth 클라이언트 ID 스푸핑이라는 새로운 회피 기법을 활용하고 있습니다. 이 기법은 사용자가 Microsoft Entra ID 환경에서 사용자 계정을 나열하고 도난당한 자격 증명을 검증할 수 있도록 합니다. 심지어 성공적인 로그인 이벤트를 생성하지 않아 방어자들을 경고하지 않게 됩니다. 이러한 공격은 클라우드 캠페인에서 이루어지고 있습니다.
── EN ──────────────────
OAuth client ID spoofing threatens attackers in Microsoft Entra ID.
At least two distinct threat actors are using a novel evasion technique called OAuth client ID spoofing. This technique allows users to enumerate accounts and validate stolen credentials in Microsoft Entra ID environments without generating a successful sign-in event that would alert defenders. This type of attack is being deployed in cloud campaigns.