Azure's Weakest Link – Full Cross-Tenant Compromise
1 hland 1 8/21/2025, 1:41:44 PM binarysecurity.no ↗
Comments (1)
hland · 2h ago
API Connections allow anyone to fully compromise any other Connection worldwide, giving full access to the connected Backend. This includes cross-tenant compromise of Key Vaults and Azure SQL databases, as well as any other externally connected service, such as Jira or SalesForce.