cognitive cybersecurity intelligence

News and Analysis

Search

50,000+ Azure AD Users Access Token Exposed From Unauthenticated API Endpoint

50,000+ Azure AD Users Access Token Exposed From Unauthenticated API Endpoint

A critical security vulnerability in Azure Active Directory affects over 50,000 users, exposing sensitive data via an unsecured API endpoint in a JavaScript file. Discovered by CloudSEK, it allows unauthorized access to Microsoft Graph with broad permissions, revealing detailed employee records, including executive information. The incident highlights significant security oversights and risks associated with misconfigured web applications.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts