> Microsoft has addressed an authorization misconfiguration for multi-tenant applications that use Azure AD, initially discovered by Wiz, and reported to Microsoft, that impacted a small number of our internal applications.
Sure, a small number of internal applications. Just the ones that gave them arbitrary JavaScript execution on every visitor to bing.com and full access to every signed in user's emails and cloud office documents.
https://msrc.microsoft.com/blog/2023/03/guidance-on-potentia...