National Cyber Warfare Foundation (NCWF)

Over 50,000 Azure AD Users’ Access Tokens Exposed via Unauthenticated API Endpoint


0 user ratings
2025-06-02 10:29:12
milo
Red Team (CNA)

CloudSEK’s BeVigil platform has uncovered a critical security vulnerability affecting an aviation giant, where an exposed JavaScript file containing an unauthenticated API endpoint led to unauthorized access to Microsoft Graph tokens with elevated privileges. This security lapse resulted in the exposure of sensitive data belonging to more than 50,000 Azure Active Directory users, highlighting significant […]


The post Over 50,000 Azure AD Users’ Access Tokens Exposed via Unauthenticated API Endpoint appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Aman Mishra

Source: gbHackers
Source Link: https://gbhackers.com/over-50000-azure-ad-users-access-tokens-exposed/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.