{"id":331280,"date":"2019-12-04T09:26:55","date_gmt":"2019-12-04T07:26:55","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=331280"},"modified":"2019-12-04T09:28:16","modified_gmt":"2019-12-04T07:28:16","slug":"microsoft-login-bug-allowed-account-hijacking","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/331280-microsoft-login-bug-allowed-account-hijacking.html","title":{"rendered":"Microsoft login bug allowed account hijacking"},"content":{"rendered":"<p>Microsoft has fixed a vulnerability in its login system which could be used to hijack user accounts.<\/p>\n<p>Cybersecurity company CyberArk found that Microsoft had left its systems vulnerable by allowing malicious parties to steal account tokens.<\/p>\n<p>These tokens are usually used to let users stay logged into websites and access third-party apps or websites without using their passwords.<\/p>\n<p>However, in research shared with <a href=\"https:\/\/techcrunch.com\/2019\/12\/02\/microsoft-login-flaw-account-hijack\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>TechCrunch<\/strong><\/a>, CyberArk found that there were numerous unregistered subdomains that were connected to Microsoft apps and were categorised as highly trusted.<\/p>\n<p>If a malicious party could trick a user into clicking a crafted link to one of these subdomains, the malicious party could then steal one of the user&#8217;s access tokens.<\/p>\n<p>CyberArk found that access tokens could be stolen in some cases with almost no user interaction &#8211; by simply using a malicious website that hides an embedded webpage.<\/p>\n<p>This would achieve the same result as getting someone to click on a link in a malicious email.<\/p>\n<p>The flaw was reported to Microsoft in October 2019 and was fixed three weeks later.<\/p>\n<p>\u201cWe resolved the issue with the applications mentioned in this report in November and customers remain protected,\u201d a Microsoft spokesperson told TechCrunch.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/cloud-hosting\/331238-amazon-reveals-new-server-chip-to-take-on-intel.html\" rel=\"bookmark\">Amazon reveals new server chip to take on Intel<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has fixed a vulnerability in its login system which could be used to hijack user accounts.<\/p>\n","protected":false},"author":341039,"featured_media":320121,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[62102,123,62104],"class_list":["post-331280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyberark","tag-microsoft","tag-microsoft-app"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331280"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341039"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=331280"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331280\/revisions"}],"predecessor-version":[{"id":331314,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331280\/revisions\/331314"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/320121"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=331280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=331280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=331280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}