Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

2026-08-26T19:23:40Z294cccc85634575d97066924e86bbb96cccd5ca05535aed88109751daeed4b56
169.254.169.254DOUBLECUPEntra IDMFAMicrosoft EntraMicrosoft GraphPNG payloadPowerShellSSRFURL/IP obfuscationauthentication logscloud metadata servicecloud securityidentity and access managementpassword sprayingprivileged accesssteganographythreat detection

What happened

SANS Internet Storm Center diary entries covering Entra ID administrative privilege review, MFA rollout gaps, Microsoft Graph and PowerShell-based risk and login monitoring, password-spray detection, SSRF attempts against cloud metadata services using hostname obfuscation, and analysis of the DOUBLECUP PNG payload. The content is defensive threat-awareness and monitoring guidance rather than a report of a confirmed compromise.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
294cccc85634575d97066924e86bbb96cccd5ca05535aed88109751daeed4b56
Enrichment time
2026-08-26T19:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.