TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.27K subscribers
Post #570 645
🔷 Azure B2C: Crypto Misuse and Account Compromise

Microsoft's Azure Active Directory B2C service contained a cryptographic flaw which allowed an attacker to craft an OAuth refresh token with the contents for any user account. An attacker could redeem this refresh token for a session token, thereby gaining access to a victim account as if the attacker had logged in through a legitimate login flow.

https://www.praetorian.com/blog/azure-b2c-crypto-misuse-and-account-compromise

#azure
  • 🔥 1
More from @cloud_sec
  1. Oct 9, 2026⚠️ Discovering and exploiting a remote code execution vulnerability in OpenCode Datadog Se…
  2. Oct 8, 2026🤖 How DigitalOcean Manages Credentials for Autonomous Agents DigitalOcean Managed Agents…
  3. Oct 7, 2026👩‍💻 Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-…
  4. Oct 6, 2026🤖 Securing the software factory at machine speed GitLab's CISO argues that agentic AI dev…
  5. Oct 5, 2026🤖 Throw Away the Playbook: Security in the AI-Native SDLC We, as an industry, should have…
  6. Oct 2, 2026🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities Google Cloud…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →