Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
2026-04-28T07:24:11Z•a174efdecacbf80f7bf3bfaeb0b0481fb5bccae1a034446d20650e248e22faca
Bitwarden CLICISA KEVCheckmarxFIRESTARTER backdoorGlassWormGopherWhisperLMDeployMicrosoft Entra IDSSRFTropic TrooperUNC6692Windows Shellactive exploitationfake VS Code extensionsfake wallet appsphishingprivilege escalationservice-principal takeoversupply chain compromise
What happened
A wave of active exploitation and supply-chain incidents was reported: Microsoft patched an Entra ID built-in role (Agent ID Administrator) vulnerability that could enable privilege escalation and service-principal takeover, and acknowledged active exploitation of Windows Shell (CVE-2026-32202). Multiple supply-chain compromises and data leaks were disclosed — Checkmarx-related GitHub data posted to the dark web, Bitwarden CLI compromised in the Checkmarx campaign, malicious Checkmarx KICS Docker images and VS Code extension attacks (GlassWorm), and 26 fake wallet apps on the App Store. High‑r
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a174efdecacbf80f7bf3bfaeb0b0481fb5bccae1a034446d20650e248e22faca
- Enrichment time
- 2026-04-28T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.