Tenable CEO says Microsoft security is blatantly negligent
bleepingcomputer.com
bleepingcomputer.com
It seems that negligence is not in short supply.
Mind you my opinion is easily permanently soured on far cooler engineering things (like Cloudflare) for them hosting doxxing things... as much as I like the engineering... if you refuse to keep people safe why would I take the risk to use your infrastructure?
Let's say a random user creates an app to measure something for their team, store it in sharepoint and update the avatar or some other property of users stored in azuread. Because of that latter part, the powerapp might (!) have requested and been granted directory.readwrite.all which means it can do anything at all including making itself or whoever can somehow control it and abuse it global admin, controlling the whole tenant.
A lot of this stuff is for business customers only, I suspect that's why you see little research or random threat actors abusing these types of features (until they're not random anymore).
I have a relative that works for them doingnthe CyberSec thing who had talked about this a few weeks ago.
Maybe they need an Azure SP3 moment?
> Redmond has since notified all impacted customers through the Microsoft 365 Admin Center starting August 4th.
> initial fix deployed by Redmond on June 7th was tagged by Tenable as incomplete
> To make matters even worse, Redmond's initial commitment to fixing the issue...
It's like how they call the US federal government "Washington".