
Eye Security
@eyesecurity
Deep dives from Eye Security’s research team.
Threat hunting, 0-days, malware, and other things we find on the internet.
ID: 2415853838
http://eye.security 28-03-2014 12:43:07
7 Tweet
72 Followers
5 Following




This afternoon at Black Hat USA, our Chief Hacker Vaisha Bernard Vaisha Bernard is breaking down how attackers can abuse Entra OAuth to pivot into internal Microsoft applications. 📍 1:30 PM | South Seas A & B, Level 3 🎯 Consent & Compromise: Abusing Entra OAuth for Fun and


🚨 From curiosity to 22 internal Microsoft apps A small distraction led to finding a common Microsoft Entra ID misconfiguration, giving access to 22+ internal Microsoft services. Last week at #BlackHatUSA, Chief Hacker Vaisha Bernard Vaisha Bernard shared the full story.
