Skip to content
Threat Feed

Product

Microsoft Graph

11 briefs RSS
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +516 roundup
10c 227i updated
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

This rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.

Entra ID +1 cloud identity api azure oauth session hijacking
2r 2t
high threat

Entra ID OAuth Device Code Phishing via AiTM

Detects successful Microsoft Entra ID sign-ins using the OAuth device code authentication protocol with the Microsoft Authentication Broker client requesting first-party Office API resources, indicative of adversary-in-the-middle (AiTM) phishing attacks such as Tycoon 2FA.

Entra ID +3 Tycoon2FA cloud identity azure entra_id phishing
2r 3t
high advisory

Microsoft 365 AiTM UserLoggedIn via Office App (Tycoon2FA)

This rule detects Microsoft 365 audit events indicative of Tycoon 2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity, identifying UserLoggedIn events where the Microsoft Authentication Broker requests access to Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents, bypassing MFA by relaying authentication and capturing session material.

Microsoft 365 +2 cloud identity saas microsoft365 aitm tycoon2fa phishing
2r 2t
medium advisory

Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins

Detects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).

Microsoft Entra ID +3 tycoon2fa aitm entra_id phishing credential_access
2r 2t
medium advisory

Microsoft Graph Multi-Category Reconnaissance Burst

The rule detects Microsoft Graph activity from delegated user tokens where a single user session and source IP rapidly touches multiple high-value Graph paths indicative of reconnaissance, suggesting a broad enumeration playbook.

Microsoft Graph cloud identity api azure microsoft-entra-id microsoft-graph threat-detection discovery
2r 2t
high advisory

Entra ID Concurrent Sign-in with Suspicious Properties

This rule identifies concurrent Azure sign-in events for the same user from multiple sources, where at least one authentication event exhibits suspicious properties associated with DeviceCode and OAuth phishing, potentially indicating refresh token theft.

Azure Entra ID +2 azure entra-id credential-access phishing
2r 4t
medium advisory

Entra ID OAuth Phishing via First-Party Microsoft Application

Attackers are leveraging first-party Microsoft applications in Entra ID to conduct OAuth phishing attacks, bypassing traditional consent prompts and accessing sensitive resources like Microsoft Graph and legacy Azure AD.

Entra ID +3 entra_id oauth phishing initial_access
2r 5t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

Entra ID User Sign-in with Unusual Client Application

Adversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.

Entra ID +1 azure entra-id initial-access oauth
2r 3t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

Detects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.

Microsoft Entra ID +2 azure entra_id oauth graph_api token_replay session_hijacking initial_access defense_evasion
2r 2t