infosec.space is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for info/cyber security-minded people. This instance blocks threads.net

Administered by:

Server stats:

46
active users

Public

Not sure if anybody else caught this, but CISA added CVE-2024-49035 to KEV a week ago - that vuln is about partner.microsoft.com being owned.

Partner.microsoft.com is a portal which allows orgs to grant access to Microsoft 365 tenants, ie read data of downstream customers. #threatintel

Public

This is the partner.microsoft.com portal, it allows CSPs - Cloud Solution Providers - to gain access to their customer's environments.

CVE-2024-49035 was around improper privilege management, i.e. being able to access things you shouldn't.

It being in CISA KEV says it was being exploited in the wild.

That portal allows a huge footprint of access by design.

@GossiTheDog the sheer fact that & can access clients' setups without proper [including / , |s and proper authorization via contract] is already sickening.

Such fundamental fuckups are reasons alone not to use or any products & services at all...

  • I mean, it doesn't require -level skills to pull this off, since it doesn't necessitate -Style or other means to gain access...
CyberplaceKevin Beaumont (@GossiTheDog@cyberplace.social)Attached: 3 images This is the partner.microsoft.com portal, it allows CSPs - Cloud Solution Providers - to gain access to their customer's environments. CVE-2024-49035 was around improper privilege management, i.e. being able to access things you shouldn't. It being in CISA KEV says it was being exploited in the wild. That portal allows a huge footprint of access by design.
Public

@kkarhan @GossiTheDog
I kicked that account out of my tenant as soon as I discovered it. Isn't that implemented differently nowadays?

Public