Microsoft Entra Actor Token Impersonated a Global Admin in Testing
CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Read article →Reader view
Choose the default article length.
Page 3 of 3
CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Read article →Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
Read article →A Teams lure installed a headless Edge extension and a Python native-messaging host, giving a ransomware access broker a quiet route to local command execution.
Read article →A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.
Read article →AIR says its brand-landingpage experiment reached 26,000 agents after scanners missed a remote instruction source that changed after approval.
Read article →CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Read article →Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Read article →Five poisoned releases avoided install hooks, launching a detached Node.js process when developer or CI tooling loaded the affected module.
Read article →Trend Micro found a Russian-speaking actor using Gemini CLI to rebuild command-and-control infrastructure and operate eight infected computers.
Read article →Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Read article →A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
Read article →The botnet gives AI workbenches priority in its scan queue, then searches compromised hosts for cloud credentials, service-account tokens, and callable tools.
Read article →A sponsored search result sent victims through a public page on claude.ai before delivering a fake desktop installer.
Read article →