Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet.&#;x26;#;xc2;&#;x26;#;xa0; &#;x26;#;xc2;&#;x26;#;xa0;It allows you to Get and Set info from/to M365, Entra Users and Entra

A recent report highlights the utility of Microsoft Graph and PowerShell for information gathering within Microsoft 365 and Entra environments, specifically focusing on the identification of stale accounts and licenses. The report suggests that while Microsoft Graph is a relatively mature API, having reached version 2.3.9, its adoption by many users and commercial tools may not yet be widespread.
Microsoft Graph serves as a unified API designed to supersede several older interfaces, offering capabilities to retrieve and modify information across various Microsoft services. In the context of this report, its application for querying Microsoft 365 and Entra ID (formerly Azure Active Directory) users and their associated attributes is emphasized. This functionality is particularly relevant for administrative tasks and security auditing.
The mechanism described involves leveraging PowerShell scripts to interact with the Microsoft Graph API. PowerShell provides a robust scripting environment for automating administrative tasks within Windows and Microsoft cloud ecosystems. By crafting specific Graph API calls through PowerShell, administrators or malicious actors can programmatically extract data related to user accounts, their status, and assigned licenses.
The focus on "stale accounts and licenses" points to a common security and operational challenge. Stale accounts, often those belonging to former employees or inactive users, can pose a security risk if not properly deprovisioned, potentially serving as lingering access points. Similarly, unmanaged or stale licenses represent unnecessary expenditure and can complicate license management.
While the report does not specify a vulnerability, it outlines a legitimate administrative capability that could be misused. The ability to programmatically enumerate and identify inactive resources is a standard function for IT administrators seeking to maintain a clean and secure environment. However, if an unauthorized entity gains access to credentials with sufficient permissions, they could leverage these same techniques to map out an organization's user base and identify potential targets or misconfigurations.
Mitigation for such information gathering typically involves robust access controls, ensuring that only authorized personnel have the necessary permissions to query sensitive directory information. Implementing the principle of least privilege, multi-factor authentication, and regular auditing of administrative accounts are standard practices. Furthermore, organizations should have established processes for identifying and deactivating stale accounts and reclaiming unused licenses to reduce both security exposure and operational overhead.
This type of reporting underscores the ongoing importance of understanding the capabilities of administrative tools and APIs within complex enterprise environments. As cloud platforms evolve and consolidate their interfaces, the potential for both efficient administration and sophisticated information gathering, whether benign or malicious, increases. Organizations must remain vigilant in securing their administrative interfaces and continuously audit access to critical directory services.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a