Security researchers have demonstrated TrustSink, a post-compromise credential-phishing technique that abuses Microsoft Entra External Authentication Methods (EAMs). An attacker who already controls a highly privileged Entra role can register a malicious external authentication provider and target selected users. During a legitimate sign-in, the provider can display a convincing Microsoft-style password prompt, capture the submitted credentials, and return a valid signed authentication token so the login completes normally. TrustSink abuses the trust relationship between Entra and externally hosted OpenID Connect (OIDC) authentication providers. The attacker-controlled provider publishes discovery metadata and signing keys, receives the authentication request, and presents a credential-collection page after the victim has already authenticated with Microsoft's legitimate service. Captured credentials can include the password, timestamp, and source IP address. The provider then generates a signed JWT containing the required authentication claims, which Entra validates against the provider's registered key before allowing access. Because authentication succeeds without an obvious error or suspicious interruption, the victim may have little indication that credentials were stolen. The technique requires significant prior privilege, such as Global Administrator or Authentication Policy Administrator, because the attacker must modify the tenant's Authentication Methods Policy. TrustSink is not an initial-access vulnerability; it becomes dangerous after administrative compromise of an Entra tenant. A malicious EAM can remain configured as a persistent credential-harvesting mechanism, meaning changing a victim's password alone may not resolve the exposure. Organizations using external authentication providers should therefore investigate unauthorized provider registrations, policy changes, OIDC metadata, signing keys, applications, and service principals associated with unfamiliar authentication infrastructure.
The threat actor known as JADEPUFFER, tracked by Microsoft as Storm-3168, has been observed carrying out destructive operations in a Microsoft Azure environment using compromised s...
Cybersecurity researchers have disclosed Carbonato, a botnet that targets Docker daemons exposed without authentication on TCP port 2375. It compromises vulnerable hosts by launchi...
Norwegian Cruise Line’s access-control system has been affected by a vulnerability tracked as CVE-2026-75907, which can allow unauthorized access through replay of an NFC keycard...