BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover
ID: 3a448239-3efa-5d5e-bcd7-a5787b934ca9
STIX ID: report--3a448239-3efa-5d5e-bcd7-a5787b934ca9
Feed Name: Wiz Blog
Threat Score
Wiz Research discovered a widespread Azure AD multi-tenant misconfiguration affecting Azure App Services and Functions that allowed authentication bypass. They demonstrated access to multiple Microsoft internal apps—most notably a Bing CMS dubbed “BingBang”—and showed they could alter search results and execute XSS that issued Office 365 tokens to exfiltrate emails, documents, and other O365 data; Microsoft fixed the issues, released guidance, and accepted the disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
