Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Bypassing logging feels relatively unimportant compared to some of the recent EntraID vulns we’ve seen


It takes a village of exploits to raise a successful and undetected attack.


Microsoft standpoint is probably: If it's undetected was there really an attack?


I dunno. It seems kinda bad that core auth log - which should be a primary source of truth during, say, a security audit - seems to work on a best-effort basis?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: