Critical Entra ID Vulnerability Allowed Global Admin Access Across All Microsoft Tenants
By
colinprince
Master baker tier. Every paragraph earns its place on the tray.
Summary
A security researcher discovered a critical vulnerability in Microsoft's Entra ID (formerly Azure AD) that could have allowed complete compromise of every Entra ID tenant worldwide. The vulnerability involved undocumented "Actor tokens" used for Microsoft's backend service-to-service communication and a flaw in the legacy Azure AD Graph API that failed to properly validate tenant origins, enabling cross-tenant access and potential global admin privileges.
Key quotes
· 4 pulledThis vulnerability could have allowed me to compromise every Entra ID tenant in the world
complete access to your tenant
undocumented impersonation tokens that Microsoft uses in their backend for service-to-service (S2S) communication, called 'Actor tokens'
critical vulnerability in the (legacy) Azure AD Graph API that did not properly validate the originating tenant
You might also wanna read
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·1d agoCISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
Security Researchers Expose Weak Encryption in Canon Enterprise Printers
During a network security assessment, security researchers discovered that Canon enterprise printers configured with default administrator c
securityboulevard.com·1d agoNew browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·2d agoCISA Contractor Exposed AWS GovCloud Credentials on Public GitHub Repository
A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository until recently that exposed
