A proof-of-concept (PoC) attack vector exploits two Azure authentication tokens from within a browser, giving threat actors persistent access to key cloud services, including Microsoft 365 applications.

  • wizardbeard@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 month ago

    Not at all, you’re absolutely right. In the Varonis article this clickbaity one references, they list out the corresponding session cookies for Google’s cloud platform and AWS as well.