Proofpoint spots Entra ID spoofing attack technique

Security researchers at Proofpoint have identified a new technique where attackers spoof OAuth client IDs to enumerate Microsoft Entra ID accounts. This method allows threat actors to validate usernames and passwords while bypassing standard security monitoring and conditional access policies.
Why it matters
This vulnerability creates a significant visibility gap for enterprise security teams, making it harder to detect password-spraying and account enumeration attacks.
Proofpoint has identified a cloud attack technique that lets threat actors enumerate Microsoft Entra ID accounts by spoofing OAuth client IDs. The method has appeared in multiple large-scale campaigns.
The article is a technical report focused on cybersecurity vulnerabilities without political or social commentary.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in