Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, …
First seen on helpnetsecurity.com
Jump to article: www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/
![]()

