Your Web News in One Place

Help Webnuz

Referal links:

Sign up for GreenGeeks web hosting
March 30, 2023 01:09 pm

Huge Microsoft exploit allowed users to manipulate Bing search results and access Outlook email accounts




A cartoon illustration shows a shadowy figure carrying off a red directory folder, which has a surprised-looking face on its side.
Microsoft has since patched the “BingBang” exploit and made changes to reduce similar vulnerabilities from occurring. | Illustration: Beatrice Sala



A dangerous vulnerability was detected in Microsoft’s Bing search engine earlier this year that allowed users to alter search results and access other Bing users’ private information from the likes of Teams, Outlook, and Office 365. Back in January, security researchers at Wiz discovered a misconfiguration in Azure — Microsoft’s cloud computing platform — that compromised Bing, allowing any Azure user to access applications without authorization.


The vulnerability was detected in the Azure Active Directory (AAD) identity and access management service. Applications using the platform’s multi-tenant permissions are accessible by any Azure user, requiring developers to validate which users can access their apps. This responsibility isn’t...



Continue reading…




Original Link: https://www.theverge.com/2023/3/30/23661426/microsoft-azure-bing-office365-security-exploit-search-results

Share this article:    Share on Facebook
View Full Article

The Verge

The Verge is an ambitious multimedia effort founded in 2011

More About this Source Visit The Verge