A sophisticated hacking campaign is making headlines after hackers exploited a previously unknown vulnerability in Microsoft’s Entra Passkey enrollment process to gain unauthorized access to Microsoft 365 accounts. The attack, which has been linked to a nation-state actor, highlights the ongoing cat-and-mouse game between cyber attackers and defenders.
The technique used by the hackers involves creating fake Entra Passkey enrollments, which are then used to bypass security measures in place for Microsoft 365 accounts. Entra Passkey is a new authentication system designed to provide secure access to multiple applications without the need for passwords. Once an attacker has created a fake enrollment, they can use it to sign into a target account, potentially gaining access to sensitive data and applications.
The attackers’ ability to create convincing fake enrollments is made possible by their knowledge of how Entra Passkey works. This authentication system relies on a form of adaptive multi-factor authentication (MFA) that uses machine learning algorithms to recognize legitimate users based on past behavior. However, if an attacker can replicate the same patterns and behaviors as a genuine user, they may be able to trick the system into granting them access.
Microsoft has yet to comment publicly on the incident, but security experts believe that this attack underscores the need for organizations to remain vigilant in their cybersecurity defenses. With AI-powered attacks becoming increasingly common, it’s essential that businesses prioritize robust security measures and stay informed about potential vulnerabilities.
The use of AI models in this type of hacking campaign highlights the evolving nature of cyber threats. As defenders rely more heavily on machine learning algorithms to detect and prevent attacks, attackers are adapting their tactics to evade detection. This cat-and-mouse game will continue to drive innovation in cybersecurity, with both sides pushing each other to stay ahead.
To mitigate risks associated with this type of attack, organizations should prioritize robust MFA settings, ensure that all employees are using secure authentication methods, and regularly review account activity for signs of suspicious behavior. Furthermore, keeping software up-to-date and patching known vulnerabilities can also help prevent similar attacks in the future.
Source: The Hacker News — 2026-07-10