Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation
2026-04-26T20:51:46Z•6f3f5cd2b78b2d6a5f03367880a48e9eee9b60cdf257e831db3450edeed96072
Agent IDBitwarden CLIClick2SMSClickFixDLL sideloadingDependabotGoGraHarvester APTHexDex arrestLOTUSLITELinux malwareMicrosoft EntraMustang PandaShai-HuludSouth AsiaTeamPCPcmdkeyfake CAPTCHApatchpersistenceprivilege escalationregsvr32service principal abusesupply-chain attacktenant takeover
What happened
Feed of security incidents and research: Microsoft patched an Entra Agent ID flaw that allowed privilege escalation via Service Principal abuse enabling tenant takeover. Infoblox disclosed a large Click2SMS fraud using fake CAPTCHAs and back-button hijacking; related ClickFix attacks trick users into running commands and abuse native Windows tools (cmdkey, regsvr32) for persistence. GitGuardian revealed TeamPCP hijacked the Bitwarden CLI and abused GitHub Dependabot to distribute the Shai‑Hulud malware and poison AI coding tools. A French suspect (HexDex) was arrested for mass data theft/leaks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 6f3f5cd2b78b2d6a5f03367880a48e9eee9b60cdf257e831db3450edeed96072
- Enrichment time
- 2026-04-26T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.