Tech

Microsoft Entra ID vulnerability allows full account takeover – and takes barely any effort

Share
Share


  • 10% of the 150,000+ SaaS apps on offer could be affected by Entra ID vulnerability
  • It was first disclosed in 2023, but many apps still remain affected
  • App vendors need to issue patches or you risk account takeover

Semperis has released new research uncovering a severe flaw in Microsoft’s Entra ID, called nOAuth, and its effects could span 10% of SaaS applications globally.

The vulnerability involves a cross-tenant authentication flaw affecting Entra ID integrations – attackers could execute full account takeover with just access to an Entra tenant and the victim’s email.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
JCB launches £649 rugged phone with wild features, but even cheaper phones threaten its survival
Tech

JCB launches £649 rugged phone with wild features, but even cheaper phones threaten its survival

JCB’s rugged phone trio enters a saturated market with a price that...

Invasive lake weed turned to clean energy in Ethiopia
Tech

Invasive lake weed turned to clean energy in Ethiopia

Fishermen on a water hyacinth-infested lake. In Ethiopia, this fast-spreading aquatic weed...

Huawei outlines telecom growth plan for China built around 130 million influencers and 10GbE deployment
Tech

Huawei outlines telecom growth plan for China built around 130 million influencers and 10GbE deployment

Huawei targets influencers to drive global 10GbE and FTTR growth China leads...

Microsoft’s rekindling of Three Mile Island nuclear plant is ahead of schedule
Tech

Microsoft’s rekindling of Three Mile Island nuclear plant is ahead of schedule

Three Mile Island nuclear plant looks to be ahead of scheduling, opening...