Keys to the Kingdom: Inside the Black Hat 2025 Authentication Breach
Keys to the Kingdom: Inside the Black Hat 2025 Authentication Breach Imagine two locks one securing legacy on-prem systems, another protecting cloud infrastructure. At Black Hat 2025, researchers showed how both can be silently picked, allowing attackers to forge tokens, impersonate users, and bypass MFA entirely. As a part-time penetration tester, that moment hit like a gut punch: even trusted identity foundations aren’t safe. This revelation underscores a crucial truth: in modern networks, defense must assume that every layer can be breached and testing must be ready to detect it. Endpoint to Entra: How Low-Privilege Accounts Can Become Admins Mollema demonstrated a method to convert a low-privilege cloud-only account into a hybrid admin via Entra ID soft matching granting full Tenant access undetected. Attackers exploited weakened syncing logic between AD and Entra ID, breaking the trusted boundary. Seamless SSO & SAML Forgery: Core Identity Trust Abused The techniques extend in...