ᅟ retweetledi
ᅟ
821 posts

ᅟ
@_harleo
tl;dr hacker / infosec analyst & researcher. mostly lurking.
0.0.0.0/0 Katılım Ekim 2017
679 Takip Edilen330 Takipçiler
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English

@pentest_swissky @mod0 Thanks for sharing! Still perplexed at how Synology handled this. This could have been devastating.
English
ᅟ retweetledi

When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365 - @mod0 / @_harleo
modzero.com/en/blog/when-b…
English
ᅟ retweetledi
ᅟ retweetledi
ᅟ retweetledi




























