2024-02-15 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 15 mars 2024\] Ajout de précision concernant les défi-réponses NTLM \[Mise à jour du 22 février 2024\] Ajout de recommandations et de précisions sur le fonctionnement de la vulnérabilité. La vulnérabilité CVE-2024-21413 permet à un attaquant de contourner les mesures de sécurité...
P5
2024-02-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.
P0
2024-01-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple vulnerabilities in Microsoft's Azure Health Bot service were discovered, allowing access to sensitive infrastructure and confidential medical data. Issues included sandbox escapes, unrestricted code execution, access to authentication secrets, cross-tenant data exposure, and unauthorized deletion of resources. Microsoft quickly patched the vulnerabilities and restructured the service architecture for improved security.
P0
2023-12-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threats evolve, and so does Huntress. Let’s talk about evolving our approach to hitting the hackers where it hurts on Microsoft 365.
P0
2023-12-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS IAM Identity Center exchanges third-party OIDC tokens for Identity Center-issued tokens. Identity Center relies on the jti claim in the third-party tokens to prevent replay attacks. Identity Center maintained a cache of previously-seen jti values for a fixed period (24 hours) and didn’t enforce that the third-party tokens had expiry claims. This meant that a token with a jti claim and without an exp claim could be replayed after >24 hours had passed.
P0
2023-12-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A way to manage Azure OpenAI deployments via the Data Plane was discovered, bypassing key security controls. This allows creation/modification/deletion of deployments without the usual protections of Resource Manager Locks, Azure Policy, and Entra ID authentication.
P0
2023-12-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
An update on our MDR for Microsoft 365 product, some recent improvements, and what fixes and features are coming soon.
P0
2023-11-22 11:20 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Actionable guide to hunting for the Windows Services abuse by using Group-IB MXDR.
P0
2023-11-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.
P0
2023-11-14 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.
P0
2023-11-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
SafeBreach Labs researchers developed methods to leverage Microsoft Azure's Automation Service for free, undetectable cryptocurrency mining. They found three ways to execute miners: two using their own environment and Azure's resources for free, and one in a victim's environment undetected. The techniques could potentially be used for any task requiring code execution on Azure.
P0
2023-10-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read up on how and why Huntress built its Managed ITDR (formerly MDR for Microsoft 365) solution to help combat the growing threat of business email compromise (BEC).
P0
2023-10-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS identified an issue in the Amazon WorkSpaces Windows client which resulted in unintentionally logging connection debugging information to a user's local system. This data could include usernames or passwords if they contain specific characters: \ (backslash) or " (double quotes). If an attacker gained access to an Amazon WorkSpaces user's machine, they could then compromise such credentials from the log.
P0
2023-09-20 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Actionable guide to hunting for the Windows Services abuse by using Group-IB MXDR.
P0
2023-08-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.
P10
2023-08-04 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…
P0
2023-08-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
P0
2023-08-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is it worth switching to Microsoft Defender Antivirus? Spoiler alert: We think yes! Explore why Defender is a solid AV solution.
P0
2023-07-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, explore how Huntress caught an attempt at financial fraud through business email compromise (BEC) in Microsoft 365.
P0
2023-07-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we explore the long-term impact of the MOVEit exploitation and how defenders can stay vigilant and learn from the past.
P0
2023-07-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Can we use anomalous user agents to detect potential business email compromise (BEC) in Microsoft 365? Explore what we found through threat hunting for BEC.
P0
2023-06-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how Huntress Managed Identity Threat Detection and Response identified three business email compromise (BEC) attacks within 72 hours of each other.
P0
2023-06-20 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft" authentication method on a web app. If an application relies on email attribute claims for authentication (which is against best practice) and also merges user accounts without proper validation, an attacker could falsify an email claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant applications with users tha…
P0
2023-06-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Everything you need to know about Microsoft's authentication control, Granular Delegated Admin Privileges (GDAP).
P0
2023-06-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…
P0
2023-03-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure on-premises data gateway allows data transfer between an on-prem customer network and several Azure cloud services, and also enables a connected agent installed locally in an on-prem network to perform certain actions remotely. NetSPI discovered a deserialization issue in Microsoft Power Platform connectors that lead to RCE on several Azure backend servers that processed call backs from on-premises data gateways, effectively allowing unauthorized cross-tenant access.
P15
2023-03-23 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…
P25
2023-03-17 14:22 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Microsoft Outlook Elevation of Privilege Vulnerability
P5
2023-03-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is tracking CVE-2023-23397, a 0-day that impacts Microsoft Outlook and requires no user interaction to expose user credential hashes.
P30
2022-12-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.
P15