Product
Microsoft Graph
- First Reported
- Sep 15, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- change is followed by a new device registration, MFA method, passkey enrollment, or unusual Microsoft Graph activity. Also detect rapid SharePoint enumeration or bulk downloads from an unfamiliar source. When ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- As a result, we packaged the same sequence of steps into a Python script (deploy.py) that drives it through Microsoft Graph in just one command: TrustSink Uses a Rogue Entra Authentication Provider to Steal Passwords
- Microsoft Graph GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens
CVE (1)
Malware (3)
People (1)
Threat Actors (6)
MITRE ATT&CK (19)
Vendors (5)
Products (17)
Tools (9)
Industries (4)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.