Skip to content
Threat Feed

Product

OneDrive for Business

4 briefs RSS
high advisory

Entra ID Device-Bound PRT Replay via First-Party Apps

Adversaries are leveraging stolen Primary Refresh Tokens (PRTs) to perform off-box authentication against Microsoft 365 services by masquerading as first-party FOCI clients from unauthorized IP addresses.

Microsoft Entra ID +4 credential-access defense-evasion cloud identity
1t
high threat

Passkey-Themed Social Engineering Targeting Microsoft Cloud Identities

Threat actors are using passkey-themed phishing and adversary-in-the-middle attacks to compromise Microsoft cloud accounts, establish persistent access via registered MFA methods, and exfiltrate data via Microsoft Graph API.

SharePoint Online +3 UNC6671 phishing cloud-security credential-harvesting mfa-bypass data-exfiltration
3t 10i
medium advisory

Detection of Unusual OAuth Application Access to SharePoint and OneDrive

This brief details a detection strategy for identifying potential OAuth phishing and illicit consent grants by monitoring for first-time application access to Microsoft 365 file storage.

SharePoint Online +1 cloud identity oauth phishing collection
1r 2t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t