Podlipodcast player Webplayer

DISCARDED: Tales From the Threat Research Trenches

DISCARDED: Tales From the Threat Research Trenches

Intercepted: How Hackers Take On the Cloud

DISCARDED: Tales From the Threat Research Trenches · Sep 3, 2026 · 54:24

0:0054:24

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

Send us fan mail!

Hello to our Cyber Pals! 

This week, Selena hands the mic over to a recording of Proofpoint's Intercepted webinar — a monthly video series she co-hosts with Sarah Sabotka — for a deep dive into how cloud brute force attacks are quietly getting more sophisticated. Joining Sarah and webinar host Jason is Rachel Rabin, a threat researcher on Proofpoint's Cloud Threat Research Team, to unpack two spoofing techniques she's seen increasingly weaponized against Microsoft Entra ID environments.

Rachel opens with the state of brute forcing today: despite flashier techniques like device code phishing and MFA-resistant phishing kits, brute force remains the most common identity attack vector, with 99% of tenants experiencing some form of it in 2026 — even though success rates typically sit well under 1%. She walks through why first-party Microsoft apps like Azure CLI and Azure AD PowerShell remain the most heavily targeted (publicly known client IDs, gaps in MFA enforcement, and pre-consented scopes), and why the legacy ROPC authentication flow makes credential testing so convenient for attackers.

From there, Rachel breaks down two techniques that "level up" traditional brute forcing:

Sarah, Jason, and the live chat also dig into:

Plus: a shoutout to next month's session on fraud and job scams ahead of Cybersecurity Awareness Month.

Resources Mentioned:

OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration — Proofpoint



Episodes: DISCARDED: Tales From the Threat Research Trenches

PodliGet the free Podli app
↓ App