Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Extracting Sensitive Information from Azure Load Testing

Summary

Azure Load Testing accepts JMeter JMX and Locust Python files that execute code in its environment, enabling Managed Identity token theft, reverse shells, and Key Vault secret extraction.
Published
Collected

original ↗