Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation

2026-04-26T20:51:46Z6f3f5cd2b78b2d6a5f03367880a48e9eee9b60cdf257e831db3450edeed96072
Agent IDBitwarden CLIClick2SMSClickFixDLL sideloadingDependabotGoGraHarvester APTHexDex arrestLOTUSLITELinux malwareMicrosoft EntraMustang PandaShai-HuludSouth AsiaTeamPCPcmdkeyfake CAPTCHApatchpersistenceprivilege escalationregsvr32service principal abusesupply-chain attacktenant takeover

What happened

Feed of security incidents and research: Microsoft patched an Entra Agent ID flaw that allowed privilege escalation via Service Principal abuse enabling tenant takeover. Infoblox disclosed a large Click2SMS fraud using fake CAPTCHAs and back-button hijacking; related ClickFix attacks trick users into running commands and abuse native Windows tools (cmdkey, regsvr32) for persistence. GitGuardian revealed TeamPCP hijacked the Bitwarden CLI and abused GitHub Dependabot to distribute the Shai‑Hulud malware and poison AI coding tools. A French suspect (HexDex) was arrested for mass data theft/leaks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
6f3f5cd2b78b2d6a5f03367880a48e9eee9b60cdf257e831db3450edeed96072
Enrichment time
2026-04-26T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation · Baitaphish