BingBang: How a simple developer mistake could have led to Bing.com takeover
ID: 76a86d69-2779-5e45-9b17-a5b5fac40511
STIX ID: report--76a86d69-2779-5e45-9b17-a5b5fac40511
Feed Name: Wiz Blog
Threat Score
Wiz Research disclosed “BingBang,” an Azure Active Directory multi-tenant misconfiguration in a Microsoft app that allowed researchers to access a Bing CMS, alter live search results, and demonstrate an XSS vector capable of stealing Office 365 access tokens from users; the issue was responsibly reported and remediated by Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
