Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    March 4, 2026

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    March 4, 2026

    Google and Epic look to bury the hatchet with new app store settlement

    March 4, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»Microsoft’s Entra ID vulnerabilities could have been catastrophic
    Tech News

    Microsoft’s Entra ID vulnerabilities could have been catastrophic

    Michael ComaousBy Michael ComaousSeptember 20, 20252 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    In this photo illustration a padlock appears next to the Microsoft Corporation logo
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    “Microsoft built security controls around identity like conditional access and logs, but this internal impression token mechanism bypasses them all,” says Michael Bargury, the CTO at security firm Zenity. “This is the most impactful vulnerability you can find in an identity provider, effectively allowing full compromise of any tenant of any customer.”

    If the vulnerability had been discovered by, or fallen into the hands of, malicious hackers, the fallout could have been devastating.

    “We don’t need to guess what the impact may have been; we saw two years ago what happened when Storm-0558 compromised a signing key that allowed them to log in as any user on any tenant,” Bargury says.

    While the specific technical details are different, Microsoft revealed in July 2023 that the Chinese cyber espionage group known as Storm-0558 had stolen a cryptographic key that allowed them to generate authentication tokens and access cloud-based Outlook email systems, including those belonging to US government departments.

    Conducted over the course of several months, a Microsoft postmortem on the Storm-0558 attack revealed several errors that led to the Chinese group slipping past cloud defenses. The security incident was one of a string of Microsoft issues around that time. These motivated the company to launch its “Secure Future Initiative,” which expanded protections for cloud security systems and set more aggressive goals for responding to vulnerability disclosures and issuing patches.

    Mollema says that Microsoft was extremely responsive about his findings and seemed to grasp their urgency. But he emphasizes that his findings could have allowed malicious hackers to go even farther than they did in the 2023 incident.

    “With the vulnerability, you could just add yourself as the highest privileged admin in the tenant, so then you have full access,” Mollema says. Any Microsoft service “that you use EntraID to sign into, whether that be Azure, whether that be SharePoint, whether that be Exchange—that could have been compromised with this.”

    This story originally appeared on wired.com.

    catastrophic Entra Microsofts vulnerabilities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleNew subscribers to Apple Music can get three free months of the Family Plan
    Next Article The Best Hybrid Mattresses for Couples, Back Pain, and More (2025)
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    4 Mins Read

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    3 Mins Read

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    2 Mins Read

    Google and Epic look to bury the hatchet with new app store settlement

    1 Min Read

    His house burned down. He used the insurance money to build PopSockets.

    1 Min Read

    Google isn’t waiting for a settlement — the 30 percent Android app store fee is dead

    7 Mins Read

    I am using the Google Pixel 10a and it’s a pretty misunderstood phone – in a good way

    Top Posts

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025564 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025564 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Our Picks

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    March 4, 2026

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    March 4, 2026

    Google and Epic look to bury the hatchet with new app store settlement

    March 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.