OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

2026-07-17T20:51:39Z4776b5e19042d3451e9ab914b5e32c9d19934956aa54e8ad7ccf908f4a08815e
active exploits protectioncredential validationcrypto theftdevice code phishinggpt-5.5microsoft entranorth-korean threat actorsoauth client id spoofingopenai partnershipphishingroundcube compromisesupply-chain/cargo theftta4922threat intelligencevulnerability prioritization

What happened

Proofpoint published a series of mid-2026 advisories and news items highlighting an increase in identity- and phishing-focused attacks and related defensive moves. Key incidents include OAuth client‑ID spoofing techniques that let attackers validate stolen Microsoft Entra credentials, new stealth methods to harvest Entra user data, device‑code phishing, and expansion of China‑linked TA4922 phishing campaigns into the UK, Germany, Italy, and South Africa. Other notable items: suspected Chinese actors targeting university Roundcube mailservers, suspected North Korean groups using fake coding‑job

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
proofpoint_blog
Record identifier
4776b5e19042d3451e9ab914b5e32c9d19934956aa54e8ad7ccf908f4a08815e
Enrichment time
2026-07-17T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials · Baitaphish