logo

The “Accidental” Breach: How a Misconfigured Endpoint Led to a Major SharePoint Data Leak

ID: 6dfc3601-05e4-5c38-9c58-bbb6bf755d2a

STIX ID: report--6dfc3601-05e4-5c38-9c58-bbb6bf755d2a

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A Trend Micro investigation details a malware-less data exfiltration where exposed Spring Boot Actuator endpoints revealed a SharePoint service account and a spreadsheet with Azure AD client secrets enabled attackers to use the Resource Owner Password Credentials flow to obtain access tokens and download sensitive SharePoint documents; recommendations include restricting Actuator access, auditing plaintext secrets, and disabling ROPC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.