Close Menu
    What's Hot

    How the S&P 500 Stock Index Became So Skewed to Tech and A.I.

    February 27, 2026

    Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

    February 27, 2026

    OpenAI Announces Major Expansion of London Office

    February 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Trend Alerts – Stay Ahead of the Trends!
    Subscribe
    • Home
    • Trending

      Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

      February 27, 2026

      OpenAI Announces Major Expansion of London Office

      February 26, 2026

      Everyone Speaks Incel Now | WIRED

      February 26, 2026

      Samsung Galaxy S26, S26+, and S26 Ultra: Specs, Features, Price, Release Date

      February 25, 2026

      H&R Block Coupons and Deals: $25 Off Tax Prep in 2026

      February 25, 2026
    • Worldwide

      Rhine Freight Market: Rising Water Levels Remove Pressure, Market Turns Defensive

      February 19, 2026

      ARA Freight Market: IE Week Dampens Demand as Rates Drift Lower

      February 18, 2026

      Rhine Freight Market: Improving Water Levels Shift the Balance Toward Softer Rates

      February 12, 2026

      ARA Freight Market: Higher Deal Count Fails to Halt Gradual Rate Softening

      February 11, 2026

      January 2026: A Volatile Start to the Year as Geopolitics Collide with Oversupply Risks

      February 6, 2026
    • Finance

      How the S&P 500 Stock Index Became So Skewed to Tech and A.I.

      February 27, 2026

      Bank not cutting your home loan rate? Should you consider loan refinancing?

      February 25, 2026

      Finance charge in credit card explained

      February 24, 2026

      How it works and why it can be dangerous

      February 23, 2026

      Bank not cutting your home loan rate? Should you refinance?

      February 22, 2026
    • Business

      5 Steps for Building Strategic Partnerships in Your Negotiations

      February 20, 2026

      How CLIMB Helped Emmanuel Aniemeke Apply Vital Business Lessons

      February 19, 2026

      How to List Certifications & Credentials on Your Resume

      February 14, 2026

      How to Build Trust in Workplace Relationships

      February 11, 2026

      5 Soft Skills to Put on a Resume & How to Prove Them

      February 10, 2026
    • News

      World’s Most Unbelievable Events That No One Expected

      March 16, 2025

      Biggest Space Discoveries That Went Viral This Year

      March 16, 2025

      AI Just Did This! The Most Shocking AI Development Yet

      March 16, 2025

      Mind-Blowing Tech Innovations That Went Viral in 2025

      March 16, 2025

      Top 10 Viral Moments That Broke the Internet in 2025

      March 16, 2025
    Trend Alerts – Stay Ahead of the Trends!
    Home»Trending»This Microsoft Entra ID Vulnerability Could Have Caused a Digital Catastrophe
    Trending

    This Microsoft Entra ID Vulnerability Could Have Caused a Digital Catastrophe

    Elon MarkBy Elon MarkSeptember 18, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in security features of major cloud providers like Microsoft. But with so much riding on these systems, there can be potentially disastrous consequences at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a pair of vulnerabilities in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts.

    Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to present at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure.

    “I was just staring at my screen. I was like, ‘No, this shouldn’’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”

    “From my own tenants—my test tenant or even a trial tenant—you could request these tokens and you could impersonate basically anybody else in anybody else’s tenant,” Mollema adds. “That means you could modify other people’s configuration, create new and admin users in that tenant, and do anything you would like.”

    Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Security Response Center on July 14, the same day that he discovered the flaws. Microsoft started investigating the findings that day and issued a fix globally on July 17. The company confirmed to Mollema that the issue was fixed by July 23 and implemented extra measures in August. Microsoft issued a CVE for the vulnerability on September 4.

    “We mitigated the newly identified issue quickly, and accelerated the remediation work underway to decommission this legacy protocol usage, as part of our Secure Future Initiative,” Tom Gallagher, Microsoft’s Security Response Center vice president of engineering, told WIRED in a statement. “We implemented a code change within the vulnerable validation logic, tested the fix, and applied it across our cloud ecosystem.”

    Gallagher says that Microsoft found “no evidence of abuse” of the vulnerability during its investigation.

    Both vulnerabilities relate to legacy systems still functioning within Entra ID. The first involves a type of Azure authentication token Mollema discovered known as Actor Tokens that are issued by an obscure Azure mechanism called the “Access Control Service.” Actor Tokens have some special system properties that Mollema realized could be useful to an attacker when combined with another vulnerability. The other bug was a major flaw in a historic Azure Active Directory application programming interface known as “Graph” that was used to facilitate access to data stored in Microsoft 365. Microsoft is in the process of retiring Azure Active Directory Graph and transitioning users to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was related to a failure by Azure AD Graph to properly validate which Azure tenant was making an access request, which could be manipulated so the API would accept an Actor Token from a different tenant that should have been rejected.



    Source link

    Catastrophe Caused Digital Entra Microsoft Vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleFed Lowers Interest Rates by Quarter Point
    Next Article What Is Coopetition & What Are Its Benefits?
    Elon Mark
    • Website

    Related Posts

    Lowe’s Promo Codes and Deals: Up to $300 Off Appliances

    February 27, 2026

    OpenAI Announces Major Expansion of London Office

    February 26, 2026

    Everyone Speaks Incel Now | WIRED

    February 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    TrendAlerts is your go-to platform for the latest trending news, covering global events, technology, business, entertainment, and more. Stay informed with real-time updates and in-depth analysis on what’s shaping the world today! 🚀

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 Trend Alerts. All Rights Are Reserved.
    • Home
    • Trending
    • Worldwide
    • Finance
    • Business
    • News

    Type above and press Enter to search. Press Esc to cancel.