July 17, 2025; CVSS 10.0 Entra ID bug via legacy Graph enabled cross-tenant impersonation risking tenant compromise.
Security researchers have found a critical vulnerability in Microsoft Entra ID which could have allowed threat actors to gain ...
A critical combination of legacy components could have allowed complete access to the Microsoft Entra ID tenant of every ...
Until Microsoft lobbed it into a virtual volcano A security researcher claims to have found a flaw that could have handed him ...
Microsoft patches CVE-2025-55241, an Azure Entra elevation of privilege vulnerability that could have been exploited to ...
Microsoft is disclosing a vulnerability that allowed hackers to obtain admin access to virtually any cloud instance of ...
Dutch security researcher Dirk-jan Mollema discovered a critical vulnerability in Microsoft Entra ID that allowed full access ...
Though patched, the flaw underscores systemic risks in cloud identity systems where legacy APIs and invisible delegation ...