OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
2026-07-17T20:51:39Z•4776b5e19042d3451e9ab914b5e32c9d19934956aa54e8ad7ccf908f4a08815e
active exploits protectioncredential validationcrypto theftdevice code phishinggpt-5.5microsoft entranorth-korean threat actorsoauth client id spoofingopenai partnershipphishingroundcube compromisesupply-chain/cargo theftta4922threat intelligencevulnerability prioritization
What happened
Proofpoint published a series of mid-2026 advisories and news items highlighting an increase in identity- and phishing-focused attacks and related defensive moves. Key incidents include OAuth client‑ID spoofing techniques that let attackers validate stolen Microsoft Entra credentials, new stealth methods to harvest Entra user data, device‑code phishing, and expansion of China‑linked TA4922 phishing campaigns into the UK, Germany, Italy, and South Africa. Other notable items: suspected Chinese actors targeting university Roundcube mailservers, suspected North Korean groups using fake coding‑job
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- proofpoint_blog
- Record identifier
- 4776b5e19042d3451e9ab914b5e32c9d19934956aa54e8ad7ccf908f4a08815e
- Enrichment time
- 2026-07-17T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.