Tech

Microsoft Entra ID vulnerability allows full account takeover – and takes barely any effort

Share
Share


  • 10% of the 150,000+ SaaS apps on offer could be affected by Entra ID vulnerability
  • It was first disclosed in 2023, but many apps still remain affected
  • App vendors need to issue patches or you risk account takeover

Semperis has released new research uncovering a severe flaw in Microsoft’s Entra ID, called nOAuth, and its effects could span 10% of SaaS applications globally.

The vulnerability involves a cross-tenant authentication flaw affecting Entra ID integrations – attackers could execute full account takeover with just access to an Entra tenant and the victim’s email.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
This ‘meh’ iPhone 17 Air camera tip might give us more insight than meets the eye
Tech

This ‘meh’ iPhone 17 Air camera tip might give us more insight than meets the eye

A ‘leaked’ image shows a screen protector for the iPhone 17 family...

JCB launches £649 rugged phone with wild features, but even cheaper phones threaten its survival
Tech

JCB launches £649 rugged phone with wild features, but even cheaper phones threaten its survival

JCB’s rugged phone trio enters a saturated market with a price that...

Invasive lake weed turned to clean energy in Ethiopia
Tech

Invasive lake weed turned to clean energy in Ethiopia

Fishermen on a water hyacinth-infested lake. In Ethiopia, this fast-spreading aquatic weed...