4 ms·
That could refer to anything from an OAuth consent attack (not much more sophisticated and arguably easier than phishing a password but much less likely to be d
by resfirestar 6y ago
That could refer to anything from an OAuth consent attack (not much more sophisticated and arguably easier than phishing a password but much less likely to be detected because most companies don't know they should be looking for it) to actual exploits against Azure AD or a third-party authentication provider. If the latter, I hope that Microsoft/FireEye decide at some point decide to be transparent about what was possible and how they're going to prevent it from happening again. I have enough doubts about AAD's ability to generate enough forensically useful logs as it is.