Microsoft Graph API - Hidden Exclusions with Overly Scoped Permissions
Hidden exclusions in Entra ID Conditional Access policies let attackers bypass MFA and use an overly scoped Graph token to enumerate tenant data.
Read ArticleHidden exclusions in Entra ID Conditional Access policies let attackers bypass MFA and use an overly scoped Graph token to enumerate tenant data.
Read ArticleExploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector
Read ArticleA bypass of the CVE-2025-0309 fix allowed enrolment to a rogue server via unauthenticated Netskope reverse-proxy routes.
Read ArticleSummary Ok, so there’s no MSI this time but our last Delinea post was titled ‘MSI Strikes Back’ so we thought we’d stay on …
Read ArticleCheck Point Harmony Local Privilege Escalation (CVE-2025-9142)
Read ArticleFootguns and privilege escalations making multi-tenancy difficult in Kubernetes clusters.
Read Article