Microsoft Patches Perfect-10 Entra ID Flaw Already Under Attack
Microsoft has fixed a maximum-severity CVSS 10.0 flaw in Entra ID, its cloud identity service used by businesses worldwide to control access to Microsoft 365 and other cloud apps, after confirming attackers were already exploiting it. No customer action is required, but Microsoft has not said who was behind the attacks or how long they had access.













