"Since the Azure AD Graph API is an older API for managing the core Azure AD / Entra ID service, access to this API could ...
A critical combination of legacy components could have allowed complete access to the Microsoft Entra ID tenant of every ...
GitHub has announced on Monday that it expanded its code hosting platform's secrets scanning capabilities for GitHub Advanced Security customers to block secret leaks automatically. Secret scanning is ...
A vulnerability that could potentially have led to the compromise of every Entra ID tenant in the world has been patched ...
Attack Surface Management Leader Enables Organizations to Check APIs for Common and Easily Exploitable API Vulnerabilities Autoswagger automatically detects authorization weaknesses in APIs and ...
Though patched, the flaw underscores systemic risks in cloud identity systems where legacy APIs and invisible delegation ...
July 17, 2025; CVSS 10.0 Entra ID bug via legacy Graph enabled cross-tenant impersonation risking tenant compromise.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results