JSON Config File Leaks Azure ActiveDirectory Credentials
ID: d51ebed5-d642-53c3-b3c3-74ee3e5ec7dd
STIX ID: report--d51ebed5-d642-53c3-b3c3-74ee3e5ec7dd
Feed Name: Dark Reading
Date Published: 2025-09-02
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Researchers found a publicly accessible ASP.NET Core appsettings.json file leaking Azure AD ClientId and ClientSecret, which would allow attackers to use the OAuth2 Client Credentials flow to obtain access tokens, query Microsoft Graph, enumerate users and permissions, and potentially escalate to tenant compromise; the report warns this is a common cloud misconfiguration and recommends removing secrets from configs, using secrets managers (Azure Key Vault/AWS Secrets Manager), rotating credentials, enforcing least privilege, and monitoring credential use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
