Hackers Exploit Microsoft Entra: New Vulnerability in Passkeys
A group of malicious actors is using social engineering to compromise Microsoft 365 accounts via fake passkey registrations in Entra.

The Rise of Targeted Social Engineering Against Microsoft Entra
Cloud security has been dealt a new blow. A sophisticated campaign led by the group identified as O-UNC-066 has recently been uncovered, using voice phishing tactics to compromise access to corporate Microsoft 365 environments. Unlike traditional attacks, this hack focuses on manipulating the passkey registration process within Microsoft Entra.
The method is deceptively simple: attackers contact employees under the guise of technical support staff, urging them to complete an urgent security registration. By accessing a phishing kit controlled by the attackers, the victim ends up linking a device controlled by the malicious actor, granting them persistent access to the corporate network.
How Does This Passkey Registration Vulnerability Work?
The effectiveness of this threat lies in its ability to bypass conventional multi-factor authentication (MFA) methods. Attackers exploit user trust in new passwordless authentication technologies.
"The threat actor O-UNC-066 uses an advanced control panel to orchestrate credential harvesting and real-time device enrollment, facilitating large-scale data extortion attacks."
Implications for Corporate Security
This incident highlights that regardless of the security updates implemented by the tech giant—such as when Microsoft patched the RoguePlanet vulnerability in Windows Defender—the human factor remains the weakest link. If attackers manage to compromise a privileged account, the next step is often the deployment of ransomware to encrypt critical data and demand astronomical payments.
To mitigate these risks, organizations must:
- Implement strict identity verification policies for any technical support requests.
- Train staff on the risks associated with new authentication methods.
- Constantly monitor audit logs for unauthorized devices linked to Entra accounts.
Conclusion
The transition toward passwordless environments is necessary, but it is not a magic bullet. The sophistication of groups like O-UNC-066 demonstrates that cybercriminals are evolving their tactics to target the very tools designed for our protection. Cybersecurity must be, above all, a culture of constant vigilance and not just a matter of software configuration.
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...