logo

BingBang: How a simple developer mistake could have led to Bing.com takeover

ID: 76a86d69-2779-5e45-9b17-a5b5fac40511

STIX ID: report--76a86d69-2779-5e45-9b17-a5b5fac40511

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2023-03-29

Date Updated: 2026-05-01

...
...

Wiz Research disclosed “BingBang,” an Azure Active Directory multi-tenant misconfiguration in a Microsoft app that allowed researchers to access a Bing CMS, alter live search results, and demonstrate an XSS vector capable of stealing Office 365 access tokens from users; the issue was responsibly reported and remediated by Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.