A critical security vulnerability in Azure Active Directory affects over 50,000 users, exposing sensitive data via an unsecured API endpoint in a JavaScript file. Discovered by CloudSEK, it allows unauthorized access to Microsoft Graph with broad permissions, revealing detailed employee records, including executive information. The incident highlights significant security oversights and risks associated with misconfigured web applications.

Cybercriminals harness AI to boost phishing & malware attacks
Artificial Intelligence (AI) tools are increasingly being used by small cybercriminal groups to develop more persistent malware, trick users into downloading malicious payloads, and create