What is Nostr?
Apicultor 🐝 /
npub18j6…x2tq
2023-07-12 11:53:04
in reply to nevent1q…nfgn

Apicultor 🐝 on Nostr: npub17lgy0…k9uux >MSA (consumer) keys and Azure AD (enterprise) keys are issued and ...

npub17lgy0rj5a2nwpnyc4hup6ufpfz7wz6dzcgd3crm6fm2yd34dcz0qlk9uux (npub17lg…9uux) >MSA (consumer) keys and Azure AD (enterprise) keys are issued and managed from separate systems and should only be valid for their respective systems. The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail.

So they were not checking which key was being used and thus a consumer key could forge Azure AD tokens.

Yikes.
Author Public Key
npub18j6utum0rs5hmukwtw2ftvf4ef00dg0peajkg7nqyefxryjae6wsgmx2tq