Crestvale Newsroom

Spoofed OAuth client IDs blind Entra logs

5 min · I går
episode Spoofed OAuth client IDs blind Entra logs cover

Description

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Identity signals are getting harder to trust. Attackers are now spoofing OAuth client IDs in Microsoft Entra ID, which means sign-in logs can misattribute the source of authentication attempts. At the same time, real-world attacks are shifting into places many teams do not continuously monitor, including browser runtime and third-party code. For security leaders, this changes how detection needs to work. Logs are no longer clean ground truth, and vendor trust cannot be static. Teams need to focus on behavior, anomaly patterns, and continuous visibility across identity systems and frontend execution. This episode also covers pre-disclosure exploitation of SonicWall SMA zero days, a browser-layer supply chain attack that led to a three million dollar loss, and AWS expanding Security Hub into a multi-cloud control plane. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comments

0

Be the first to comment

Sign up now and become a member of the Crestvale Newsroom community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

178 episodes

episode Spoofed OAuth client IDs blind Entra logs artwork

Spoofed OAuth client IDs blind Entra logs

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Identity signals are getting harder to trust. Attackers are now spoofing OAuth client IDs in Microsoft Entra ID, which means sign-in logs can misattribute the source of authentication attempts. At the same time, real-world attacks are shifting into places many teams do not continuously monitor, including browser runtime and third-party code. For security leaders, this changes how detection needs to work. Logs are no longer clean ground truth, and vendor trust cannot be static. Teams need to focus on behavior, anomaly patterns, and continuous visibility across identity systems and frontend execution. This episode also covers pre-disclosure exploitation of SonicWall SMA zero days, a browser-layer supply chain attack that led to a three million dollar loss, and AWS expanding Security Hub into a multi-cloud control plane. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Yesterday5 min
episode wp2shell pre-auth RCE: WordPress 7.0.2 out artwork

wp2shell pre-auth RCE: WordPress 7.0.2 out

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A forced WordPress update, agentic browser risks, and a shift in supply chain attacks all point to the same problem: trust is being exploited faster than teams can validate it. For security and IT leaders, this is a change in where risk lives. Core platforms can be compromised without credentials, browser extensions can act with user privileges, and dependency updates can carry malicious code straight into CI. At the same time, ransomware operators are prioritizing identity access over traditional exploits. The result is a compressed window between exposure and impact. We also cover Microsoft's view on npm trust path attacks, new risks in AI browser agents, and why identity is again the primary entry point for ransomware. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

19. juli 20266 min
episode DigiCert breach linked to code-signing theft artwork

DigiCert breach linked to code-signing theft

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A breach tied to DigiCert has put code signing certificates in attacker hands, turning a core trust signal into a potential attack vector. At the same time, ransomware is now disrupting real world operations, and vendor risk is showing up in places many teams assume are safe. This episode breaks down why trust in signed software can no longer be assumed, how ransomware is shifting toward direct revenue disruption, and why identity and secrets platforms need deeper scrutiny. The common thread is control. Who has it, how it is verified, and where it quietly fails. We also cover CrowdStrike's move to absorb XM Cyber's technology, a ransomware driven production shutdown at Fairlife, and new concerns around Passwork's origins. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

18. juli 20265 min
episode Microsoft: AI agents need first-class identities artwork

Microsoft: AI agents need first-class identities

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] AI agents are no longer just assistants. They are becoming active participants inside systems, with the ability to take actions across tools and services. That shift is forcing a rethink of identity, access, and control. For security and IT leaders, this changes the threat model. Agents introduce new forms of privilege escalation, cross-system risk, and audit gaps that traditional identity frameworks were not built to handle. At the same time, regulatory pressure and real-world breaches are reinforcing that weak identity controls remain the easiest path for attackers. This episode also covers the CMMC audit pause and why liability remains, new developments tied to Scattered Spider, and Google's move into AI-driven app execution. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

17. juli 20266 min
episode CISA: SharePoint exploits active, patching lags artwork

CISA: SharePoint exploits active, patching lags

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Active SharePoint exploitation with delayed patches is exposing a growing gap between vulnerability discovery and real world remediation. At the same time, identity is expanding beyond humans, and patching volume is accelerating beyond what most teams can handle. This episode breaks down why these shifts matter now. If attackers are exploiting before fixes arrive, your defenses have to operate in that window. And as machine and agent identities grow, traditional access control models are starting to fail. The result is a security environment that is faster, more complex, and less forgiving of delay. We also cover new funding around identity control planes, a record-breaking patch cycle from Microsoft, and a major milestone in post-quantum cryptography standardization. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

16. juli 20265 min