Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Entra ID adds CSP enforcement to block script injection during sign-ins

Security Tool/Service
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft Entra ID is rolling out Content Security Policy (CSP) enforcement for browser-based sign-ins, blocking external script injection and reducing XSS-driven credential theft risk. The change applies to login.microsoftonline.com and limits authentication pages to trusted Microsoft-hosted scripts. Microsoft says the rollout starts in mid-October 2026 and finishes by late October 2026. Enterprises using browser extensions or tools that inject code into sign-in pages may need to test for blocked-script violations before the deadline.

Related Happenings

TrustSink rogue external MFA provider attack against Microsoft Entra

Technical Analysis
H score30 First: 23.09.2026 00:45 Last: 23.09.2026 00:45 Sources 1

About this happening: Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creatin...

Windows 11 KB5124008 Active Directory domain trust breakage

Service Disruption
H score0 First: 16.09.2026 23:39 Last: 16.09.2026 23:39 Sources 1

About this happening: The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microso...

Latest development: 17.09.2026 11:24

Microsoft shared a temporary workaround for Windows 11 systems where the September 2026 security updates trigger Machine Identity Isolation enforcement and break domain trust and valid credential sign-ins on enterprise devices. Admins should disable Machine Identity Isolation using the same method used to enable it, restart the device, and reset the secure channel; Microsoft also says the feature is only supported in environments connected to Windows Server 2025 Domain Functional Level (DFL) and above.

Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)

Vulnerability
H score49 First: 21.08.2026 09:06 Last: 21.08.2026 09:06 Sources 1

About this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
H score31 First: 10.08.2026 15:25 Last: 10.08.2026 15:25 Sources 1

About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Timeline

  1. 30.09.2026 16:37 2 articles · 1h ago

    Microsoft Entra ID will enforce CSP to block external script injection

    Mitigation Patch Update

    Microsoft is telling customers that Entra ID browser-based sign-ins will be protected by Content Security Policy enforcement that allows only trusted Microsoft-hosted scripts from CDN domains, blocking external script injection and reducing cross-site scripting risk on login.microsoftonline.com. Enterprise customers are being advised to stop using browser extensions and other tools that inject code into sign-in pages and to test sign-in scenarios for blocked-script violations before the rollout completes, while Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected.

    Show sources