Post by Cloud Village

3,214 followers

πŸ”₯ DECODING ENTRA ID EXPLOITATION πŸ”₯ How virtually ignored threat vectors put all Entra ID customers at risk via OAuth and device registration abuse? In this classic session spotlight, Jenko Hwong breaks down the mechanics of the Storm-2372 campaignβ€”exposing how threat actors weaponized OAuth Device Code Phishing, hijacked Primary Refresh Tokens (PRTs), and bypassed traditional defensive monitoring. Get ready to pull apart complex API logs and look on-the-wire at identity threats before we head to DEF CON 34 Cloud Village's Apex Park! πŸ¦–πŸΉ πŸ‘‡ Catch the full technical breakdown linked in the replies below πŸ‘‡ #CloudSecurity #EntraID #IdentitySecurity #DEFCON #CloudVillage #Infosec

Post content

Video Content