Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

nOAuth Abuse Alert: Full Account Takeover of Entra Cross-Tenant SaaS Applications

Summary

Semperis found 9 of 104 tested SaaS apps vulnerable to nOAuth abuse: with an Entra tenant and a victim's email, an attacker can take over accounts. The flaw is severe and hard to defend against.
Published
Collected

original ↗