TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.27K subscribers
Post #889 649
👩‍💻 Arbitrary 1-click Azure tenant takeover via MS application

This blog explains how reply URLs in Azure Applications can be used as a vector for phishing. The impact of this can range from data leaks to complete tenant takeover; just by luring a victim into clicking on a link.

https://falconforce.nl/arbitrary-1-click-azure-tenant-takeover-via-ms-application/

#azure
  • 🔥 3
  • ❤ 1
  • 👍 1
More from @cloud_sec
  1. Oct 2, 2026🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities Google Cloud…
  2. Oct 1, 2026🔶 Exploring the new AWS Sign Up experience This post will explore what this new concept d…
  3. Sep 30, 2026🤖 Hacking OpenAI Researchers chained a libheif heap buffer overflow (via Discourse/ImageM…
  4. Sep 29, 2026👩‍💻 How to secure edge AI in customer-owned environments Edge AI shifts trust responsibi…
  5. Sep 28, 2026🤖 Containers Are No Longer a Security Boundary AI-accelerated kernel vuln discovery (5,97…
  6. Sep 25, 2026🔶 Introducing Amazon EBS Volume Clones across AWS account AWS introduces Amazon EBS Volum…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →