ctipilot.ch
← Back to Weekly 2026-W21
HIGHsynthesis

Midnight Blizzard and others operationalise ROADtools for Entra ID abuse

discovered 2026-05-18 05:00 UTCrun 2026-W21-473d6fa52 sourcesmulti-source

Unit 42 documented systematic nation-state operationalisation of the open-source ROADtools Entra ID framework by Midnight Blizzard, Curious Serpens and UTA0355 for device registration, token theft and tenant enumeration (daily 2026-05-23). This is the most broadly relevant item in the section — every M365/Entra tenant is in scope. Hunt for unexpected device-registration events, anomalous service-principal token requests, and ROADtools-characteristic enumeration patterns; tighten conditional-access on device-registration and review legacy-auth exposure.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.