Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

2026-04-28T07:24:11Za174efdecacbf80f7bf3bfaeb0b0481fb5bccae1a034446d20650e248e22faca
Bitwarden CLICISA KEVCheckmarxFIRESTARTER backdoorGlassWormGopherWhisperLMDeployMicrosoft Entra IDSSRFTropic TrooperUNC6692Windows Shellactive exploitationfake VS Code extensionsfake wallet appsphishingprivilege escalationservice-principal takeoversupply chain compromise

What happened

A wave of active exploitation and supply-chain incidents was reported: Microsoft patched an Entra ID built-in role (Agent ID Administrator) vulnerability that could enable privilege escalation and service-principal takeover, and acknowledged active exploitation of Windows Shell (CVE-2026-32202). Multiple supply-chain compromises and data leaks were disclosed — Checkmarx-related GitHub data posted to the dark web, Bitwarden CLI compromised in the Checkmarx campaign, malicious Checkmarx KICS Docker images and VS Code extension attacks (GlassWorm), and 26 fake wallet apps on the App Store. High‑r

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a174efdecacbf80f7bf3bfaeb0b0481fb5bccae1a034446d20650e248e22faca
Enrichment time
2026-04-28T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.