loader image
Microsoft Entra ID Used to Steal Azure, M365 Data

Microsoft Entra ID was recently exploited by hackers in a sophisticated cyberattack targeting Microsoft 365 and Azure data. This incident involved a compromised version of the Nx Console VS Code extension, which appeared on the Visual Studio Code Marketplace on May 18, 2026. The malware targeted developer credentials, cloud tokens, and CI/CD secrets, spreading across thousands of machines. In mere seconds after a developer accessed any workspace, the malicious extension executed a complex payload designed for credential theft. Despite being active for just 11 minutes, this attack maximized data exfiltration, utilizing Sigstore attestation to potentially propagate further. The incident, marking the second supply chain attack on the Nx ecosystem within a year, highlights vulnerabilities in open-source tools. Developers are advised to update to version 18.100.0 to mitigate risks. As threats persist, understanding how Microsoft Entra ID was used becomes crucial for enhancing cybersecurity measures.

For further details, read the full article:

Hackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data

Write a Reply or Comment

Your email address will not be published. Required fields are marked *