The “Accidental” Breach: How a Misconfigured Endpoint Led to a Major SharePoint Data Leak
ID: 6dfc3601-05e4-5c38-9c58-bbb6bf755d2a
STIX ID: report--6dfc3601-05e4-5c38-9c58-bbb6bf755d2a
Feed Name: securityonline.info
Threat Score
A Trend Micro investigation details a malware-less data exfiltration where exposed Spring Boot Actuator endpoints revealed a SharePoint service account and a spreadsheet with Azure AD client secrets enabled attackers to use the Resource Owner Password Credentials flow to obtain access tokens and download sensitive SharePoint documents; recommendations include restricting Actuator access, auditing plaintext secrets, and disabling ROPC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
