Lemmy.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
dirtmayor@beehaw.org to Technology@beehaw.orgEnglish · 2 years ago

Azure AD 'Log in With Microsoft' Authentication Bypass Affects Thousands

www.darkreading.com

external-link
message-square
1
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
11
external-link

Azure AD 'Log in With Microsoft' Authentication Bypass Affects Thousands

www.darkreading.com

dirtmayor@beehaw.org to Technology@beehaw.orgEnglish · 2 years ago
message-square
1
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
The "nOAuth" attack allows cross-platform spoofing and full account takeovers, and enterprises need to remediate the issue immediately, researchers warn.
alert-triangle
You must log in or register to comment.
  • AlternateRoute
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 years ago

    Already patched and they informed customers where this may have been used.

    https://www.bleepingcomputer.com/news/security/microsoft-fixes-azure-ad-auth-flaw-enabling-account-takeover/

    “To protect customers and applications that may be vulnerable to privilege escalation, Microsoft has deployed mitigations to omit token claims from unverified domain owners for most applications.”

Technology@beehaw.org

technology@beehaw.org

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 110 users / day
  • 1.54K users / week
  • 3.2K users / month
  • 7.7K users / 6 months
  • 1.32K local subscribers
  • 38.6K subscribers
  • 4.89K Posts
  • 89.7K Comments
  • Modlog
  • mods:
  • alyaza [they/she]@beehaw.org
  • TheRtRevKaiser@beehaw.org
  • gyrfalcon@beehaw.org
  • rs5th@beehaw.org
  • coldredlight@beehaw.org
  • Leigh@beehaw.org
  • TheRtRevKaiser@kbin.social
  • Chris Remington@beehaw.org
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org