Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phantom Device Exploits Bypass Azure AD Security

Phantom Device Exploits Bypass Azure AD Security

Posted on May 6, 2026 By CWS

Cloud identity management is a cornerstone of modern cybersecurity, with Microsoft Entra ID (formerly Azure AD) Conditional Access playing a pivotal role. This system evaluates user locations, risk levels, and device compliance before granting access, acting as a crucial digital gatekeeper.

Critical Vulnerabilities Uncovered

An authorized red team assessment by Howler Cell has revealed a significant vulnerability that circumvents these essential protections. By leveraging valid credentials, which can be obtained for a relatively low price on underground markets, researchers successfully infiltrated a tenant hosting over 16,000 users. This breach occurred without deploying malware or interacting with corporate devices, underscoring weaknesses in device registration and compliance checks.

Exploiting Device Registration Service Flaws

The attack strategy mirrored techniques employed by Storm-2372, a group believed to be linked to Russian state actors. Both parties exploited vulnerabilities in the Device Registration Service (DRS) endpoints to gain initial access, illustrating that even blocked credentials can be a starting point for adept attackers.

Howler Cell’s findings highlight how attackers bypassed CA policies resulting in an AADSTS53003 error. By targeting the DRS endpoint through an unprotected device code authentication flow, researchers managed to carry out the attack successfully.

Phantom Device Registration and PRT Manipulation

The team registered a phantom device using a signed Azure AD certificate and private key, exploiting the DRS API’s lack of verification for physical Windows machines. This allowed a Linux-based device to pose as a legitimate endpoint, employing the MITRE ATT&CK technique for Account Manipulation (T1098.005).

With the phantom device in place, a Primary Refresh Token (PRT) was generated with falsified device claims. When exchanged for an access token, Azure AD mistakenly recognized the session as device-authenticated, thus bypassing CA policies requiring compliant devices.

Implications and Defense Strategies

Further investigation revealed that the phantom device successfully bypassed Intune’s enrollment restrictions by claiming hybrid domain-join status. This allowed the device to be recognized as compliant, despite missing essential security features like BitLocker.

Howler Cell identified additional risks within hybrid identity environments. They found 255 highly privileged directory roles, including Global Administrators, synced from on-premises Active Directory, offering a direct avenue for a complete tenant takeover.

To mitigate these vulnerabilities, organizations need to reinforce their device trust models. Suggested measures include enforcing Conditional Access policies that block device code flows, mandating TPM 2.0 attestation for PRT issuance, and requiring external device health validation through Microsoft Health Attestation Service. Additionally, limiting privileged directory roles to cloud-only accounts managed via Privileged Identity Management can provide further protection.

Stay informed on the latest cybersecurity insights by following us on Google News, LinkedIn, and X. For more information or to share your story, contact us today.

Cyber Security News Tags:Azure AD, cloud security, Conditional Access, Cybersecurity, device registration, Howler Cell, Intune compliance, Microsoft Entra ID, phantom device, PRT abuse

Post navigation

Previous Post: Google Enhances Android Security with Binary Transparency
Next Post: CloudZ Malware Exploits Phone Link for Credential Theft

Related Posts

CISA Expands KEV Catalog with 1,484 New Vulnerabilities as Active Exploitation Surges 20% in 2025 CISA Expands KEV Catalog with 1,484 New Vulnerabilities as Active Exploitation Surges 20% in 2025 Cyber Security News
GitGuardian Launches MCP Server to Bring Secrets Security into Developer Workflows GitGuardian Launches MCP Server to Bring Secrets Security into Developer Workflows Cyber Security News
NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks Cyber Security News
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign 4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign Cyber Security News
Hackers Exploiting VMware ESXi Instances in the Wild Using zero-day Exploit Toolkit Hackers Exploiting VMware ESXi Instances in the Wild Using zero-day Exploit Toolkit Cyber Security News
Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NGINX Vulnerability CVE-2026-42945 Actively Exploited
  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NGINX Vulnerability CVE-2026-42945 Actively Exploited
  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark