URL has been copied successfully!
Over 50,000 Azure AD Users’ Access Tokens Exposed via Unauthenticated API Endpoint
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Over 50,000 Azure AD Users’ Access Tokens Exposed via Unauthenticated API Endpoint

CloudSEK’s BeVigil platform has uncovered a critical security vulnerability affecting an aviation giant, where an exposed JavaScript file containing an unauthenticated API endpoint led to unauthorized access to Microsoft Graph tokens with elevated privileges. This security lapse resulted in the exposure of sensitive data belonging to more than 50,000 Azure Active Directory users, highlighting significant […] The post Over 50,000 Azure AD Users’ Access Tokens Exposed via Unauthenticated API Endpoint appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/over-50000-azure-ad-users-access-tokens-exposed/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link