Data theft from millions of Office365 customers
A security researcher was able to place his own results at the top of Bing, Microsoft’s search engine, and add malware to them. He could have used it to steal access cookies from logged-in Office365 customers. Azure Active Directory is offered by Microsoft as a cloud service, but is also used for internal identity management services. The security researcher was able to gain access to internal administration tools for the Bing search engine through a misconfiguration.
Continue Reading