June 21, 2023, 11:38 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

A security shortcoming in Microsoft Azure Active Directory (AD) Open Authorization (OAuth) process could have been exploited to achieve full account takeover, researchers said.
California-based identity and access management service Descope, which discovered and reported the issue in April 2023, dubbed it nOAuth.
"nOAuth is an authentication implementation flaw that can affect Microsoft Azure AD

access access management account account takeover active directory april authentication authorization azure azure active directory azure ad california critical directory exploited flaw identity identity and access identity and access management implementation issue management microsoft microsoft azure microsoft azure ad noauth oauth process researchers security service takeover

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC