TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.27K subscribers
Post #1209 438
👩‍💻 I SPy: Escalating to Entra ID's Global Admin with a first-party app

Backdooring Microsoft's applications is far from over. A vulnerable, built-in SP that could have allowed escalation from Application Administrator to any hybrid tenant user, including Global Admin, was discovered.

https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/

#azure
  • ❤ 1
  • 👍 1
  • 🔥 1
More from @cloud_sec
  1. Sep 29, 2026👩‍💻 How to secure edge AI in customer-owned environments Edge AI shifts trust responsibi…
  2. Sep 28, 2026🤖 Containers Are No Longer a Security Boundary AI-accelerated kernel vuln discovery (5,97…
  3. Sep 25, 2026🔶 Introducing Amazon EBS Volume Clones across AWS account AWS introduces Amazon EBS Volum…
  4. Sep 24, 2026🤖 DeepSeek Harness Vulnerability. Lets AI Agents Escape Their Own Sandbox CVE-2026-82533…
  5. Sep 23, 2026🤖 Hacking AI customer service agents Techniques for attacking AI customer service agents:…
  6. Sep 22, 2026🤖 OpenAI's Defense Factory OpenAI's Defense Factory is a continuous, agent-first vulnerab…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →