logo

BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover

ID: 3a448239-3efa-5d5e-bcd7-a5787b934ca9

STIX ID: report--3a448239-3efa-5d5e-bcd7-a5787b934ca9

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2023-03-29

Date Updated: 2026-05-01

...
...

Wiz Research discovered a widespread Azure AD multi-tenant misconfiguration affecting Azure App Services and Functions that allowed authentication bypass. They demonstrated access to multiple Microsoft internal apps—most notably a Bing CMS dubbed “BingBang”—and showed they could alter search results and execute XSS that issued Office 365 tokens to exfiltrate emails, documents, and other O365 data; Microsoft fixed the issues, released guidance, and accepted the disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.