<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Token Theft Series on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/token-theft-series/</link>
    <description>Recent content in Token Theft Series on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 17 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/token-theft-series/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ERNW White Paper 80: Token Theft in Microsoft Entra ID - An Analysis of Controls</title>
      <link>https://insinuator.net/2026/08/ernw-white-paper-80-token-theft-in-microsoft-entra-id-an-analysis-of-controls/</link>
      <pubDate>Mon, 17 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/ernw-white-paper-80-token-theft-in-microsoft-entra-id-an-analysis-of-controls/</guid>
      <description>&lt;p&gt;While most attacks against cloud identities still rely on traditional password-based techniques, such as password spraying, credential stuffing, and brute-force attacks, these methods have become less effective as multi-factor authentication (MFA) has become more widespread. As a result, attackers are increasingly turning to token-based techniques, including token theft, adversary-in-the-middle (AiTM) attacks, device code phishing, and ConsentFix, which get around MFA instead of trying to break it.&lt;/p&gt;&#xA;&lt;p&gt;As one of the most widely deployed identity platforms, Microsoft Entra ID is a prime target for these evolving attack techniques. This raises the question: how well does its &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/devices/protecting-tokens-microsoft-entra-id#defense-in-depth-strategy-against-token-theft&#34;&gt;defense-in-depth strategy&lt;/a&gt; actually hold up against this shift? We put it to the test.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
