Aug. 1, 2023, 10:16 p.m. | Emile Antone

Security Boulevard securityboulevard.com

In several recent investigations of SaaS security incidents, the Obsidian threat research team identified a novel attack vector in the wild: abuse of the Azure AD self-service password reset (SSPR) feature. With the glaring lack of coverage around this specific threat vector, our team felt it would be an important topic for discussion. In this […]


The post Behind The Breach: Self-Service Password Reset (SSPR) Abuse in Azure AD appeared first on Obsidian Security.


The post Behind The Breach: …

abuse attack attack vector azure azure ad breach feature featured incidents investigations novel obsidian password password reset research reset saas saas security security security advisories service team threat threat research threat vector

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC