ZeroHour

Search: “intune”

4 stories in the last 24h

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

eSentire exposes GhostCode, a device-code phishing kit that abuses Microsoft Entra device enrollment to persist even after stolen tokens are revoked.

eSentire's Threat Response Unit observed GhostCode campaigns in late August 2026, using BEC-style social engineering that impersonated procurement staff, including BJ's Wholesale Club, via Salesforce contact forms. Victims received password-protected HTML lures disguised as a FlipBook document portal, with junk-data padding, HTML comment injection, and AES-256-GCM encrypted redirects gated by anti-bot checks. The kit exploits the OAuth 2.0 device authorization grant, prompting victims to approve real Microsoft device-code sign-ins with MFA. Within 78 seconds of approval, attackers registered three Entra devices and obtained a Primary Refresh Token, so rogue device registrations persist even after session token revocation.

GBHackers · 14h agoPhishing & fraud in the wild2

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.

eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.

Cyber Security News · 13h agoPhishing & fraud in the wild 9 sources5

Windows 11 KB5124008 Update Breaks Active Directory Domain Trust and Blocks User Logins

Microsoft's September Windows 11 cumulative update KB5124008 breaks Active Directory domain trust on domain-joined machines, blocking logins despite valid credentials.

Microsoft is investigating community reports that KB5124008, the September 8, 2026 cumulative update for Windows 11 24H2/25H2 (builds 26100.9445/26200.9445), breaks the AD secure channel, causing 'The user name or password is incorrect' errors on interactive logon. Admins reproduced the failure consistently and observed nltest error 1786 (ERROR_NO_TRUST_LSA_SECRET) plus domain controller Event 4625 with status 0xC000006D over NTLM. The problem is suspected in Machine Identity Isolation, a Credential Guard capability that moves machine-account secrets into virtualization-based security, and disabling it via registry value, Group Policy, or Intune baseline restored trust. The September 14 out-of-band update KB5129195 does not address the domain trust issue, and Microsoft's release notes do not list it as a known problem.

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

Cyber Security News · 20h agoVulnerability in the wildCVE-2026-62721