
nOAuth-ing to see here. [Research Saturday]
CyberWire Daily
00:00
Vulnerabilities in Entra Cross-Tenant SaaS Applications
This chapter explores the vulnerabilities in Entra Cross-Tenant SaaS Applications, focusing on NoAuth abuse and the potential for account takeovers. The speakers detail their testing methods, ethical considerations, and the importance of legitimate accounts while uncovering security weaknesses, particularly in applications dealing with PII. It also highlights the challenges in securing these applications and the inherent risks associated with the implementation of OpenID Connect by vendors.
Transcript
Play full episode