🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)

🪟 Windows Tipps 🕛 vor 3 Jahren 4 Min Lesezeit
0

Researcher breaks in to Bing, Office 365 via AAD misconfiguration, now fixed

↗ Quelle (onmsft.com)
🗣️ Stimme:

Wiz, a cybersecurity firm discovered a major CMS that allowed me to alter search results and take over millions of … 👀
This is the story of


— Hillai Ben-Sasson (@hillai) , Ami Luttwak, the chief technology officer at Wiz stated that “A potential attacker could have influenced Bing search results and compromised Microsoft 365 emails and data of millions of people. It could have been a nation-state trying to influence public opinion or a financially motivated hacker.”


According to Wiz:


The issues we identified in this research may affect any organization with Azure Active Directory applications that have been configured as multi-tenant but lack sufficient authorization checks. Based on data from our scans, we assess that exposure is significantly more common across Azure App Service and Azure Functions applications, where validation responsibility is unclear to developers.


The cybersecurity firm details that attackers hadn’t leveraged the vulnerability to deploy their phishing attacks to unsuspecting users. Wiz reported the issue to Microsoft’s Security Response Center on January 31. Microsoft quickly acknowledged it and issued a fix on Feb 2, a few days before mark. Had the issue not been patched in time for the launch or not discovered at all, the potential risk and threat in place would have been unimaginable. Microsoft has indicated that it is invested in putting elaborate measures to ensure that the user’s security and privacy is maintained.


It’s important for admins to ensure that multi-tenant access is properly configured. Wiz has since

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf onmsft.com.
↗ Original-Artikel auf onmsft.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
ChatGPT automatically logged out [Fix]
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Researcher breaks in to Bing, Office 365 via AAD misconfiguration, now fixed

Thematisch verwandte Begriffe: Researcher, breaks, Bing, Office · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...