Close Menu
Global News HQ
    What's Hot

    13 Incredible Space Museums in the U.S. Every Traveler Should Visit

    December 13, 2025

    Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)

    December 13, 2025

    Kallmeyer Pre-Fall 2026 Collection

    December 13, 2025
    Recent Posts
    • 13 Incredible Space Museums in the U.S. Every Traveler Should Visit
    • Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)
    • Kallmeyer Pre-Fall 2026 Collection
    • The Top 10 New Patios and Decks of 2025
    • WWE Superstars visit pediatric research participants at NIH Clinical Center and The Children’s Inn
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • 13 Incredible Space Museums in the U.S. Every Traveler Should Visit
    • Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)
    • Kallmeyer Pre-Fall 2026 Collection
    • The Top 10 New Patios and Decks of 2025
    • WWE Superstars visit pediatric research participants at NIH Clinical Center and The Children’s Inn
    • Ripple Scores Major Victories but XRP’s Price Continues to Fight for Survival at $2
    • Celebrate the 12 Days of Cheese with Whole Foods’ Holiday Promotion
    • EU freezes Russian assets ahead of pivotal Ukraine talks
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Technology & Gadgets - Microsoft’s Entra ID vulnerabilities could have been catastrophic
    Technology & Gadgets

    Microsoft’s Entra ID vulnerabilities could have been catastrophic

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Microsoft’s Entra ID vulnerabilities could have been catastrophic
    Share
    Facebook Twitter LinkedIn Pinterest Email



    “Microsoft built security controls around identity like conditional access and logs, but this internal impression token mechanism bypasses them all,” says Michael Bargury, the CTO at security firm Zenity. “This is the most impactful vulnerability you can find in an identity provider, effectively allowing full compromise of any tenant of any customer.”

    If the vulnerability had been discovered by, or fallen into the hands of, malicious hackers, the fallout could have been devastating.

    “We don’t need to guess what the impact may have been; we saw two years ago what happened when Storm-0558 compromised a signing key that allowed them to log in as any user on any tenant,” Bargury says.

    While the specific technical details are different, Microsoft revealed in July 2023 that the Chinese cyber espionage group known as Storm-0558 had stolen a cryptographic key that allowed them to generate authentication tokens and access cloud-based Outlook email systems, including those belonging to US government departments.

    Conducted over the course of several months, a Microsoft postmortem on the Storm-0558 attack revealed several errors that led to the Chinese group slipping past cloud defenses. The security incident was one of a string of Microsoft issues around that time. These motivated the company to launch its “Secure Future Initiative,” which expanded protections for cloud security systems and set more aggressive goals for responding to vulnerability disclosures and issuing patches.

    Mollema says that Microsoft was extremely responsive about his findings and seemed to grasp their urgency. But he emphasizes that his findings could have allowed malicious hackers to go even farther than they did in the 2023 incident.

    “With the vulnerability, you could just add yourself as the highest privileged admin in the tenant, so then you have full access,” Mollema says. Any Microsoft service “that you use EntraID to sign into, whether that be Azure, whether that be SharePoint, whether that be Exchange—that could have been compromised with this.”

    This story originally appeared on wired.com.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleYou’ll enjoy the Specialized Turbo Vado SL 2 6.0 Carbon even without assist
    Next Article The Harvard Doctor Who Says We've Been Wrong About Stress This Whole Time

    Related Posts

    Wordle today: The answer and hints for December 13, 2025

    December 13, 2025

    The Verge’s 2025 holiday gift guide

    December 13, 2025

    I'm a shopping editor, and this is the No. 1 reason I prefer Best Buy over Amazon for tech purchases

    December 13, 2025

    AMD CEO Lisa Su Isn’t Afraid of the Competition

    December 13, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Travel & Tourism (Luxury)
    10 Mins Read

    13 Incredible Space Museums in the U.S. Every Traveler Should Visit

    More than six decades ago, the United States launched its first satellite into Earth orbit,…

    Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)

    December 13, 2025

    Kallmeyer Pre-Fall 2026 Collection

    December 13, 2025

    The Top 10 New Patios and Decks of 2025

    December 13, 2025
    Top
    Travel & Tourism (Luxury)
    10 Mins Read

    13 Incredible Space Museums in the U.S. Every Traveler Should Visit

    More than six decades ago, the United States launched its first satellite into Earth orbit,…

    Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)

    December 13, 2025

    Kallmeyer Pre-Fall 2026 Collection

    December 13, 2025
    Our Picks
    Travel & Tourism (Luxury)
    10 Mins Read

    13 Incredible Space Museums in the U.S. Every Traveler Should Visit

    More than six decades ago, the United States launched its first satellite into Earth orbit,…

    Finance & Investment
    1 Min Read

    Amrize Stock: A Dual-Engine Compounder In The Making (NYSE:AMRZ)

    Amrize: A Dual-Engine Compounder In The Making Source link

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version