Daily Breach

Vulnerability

Critical Azure SSO Token Flaw in Windows Admin Center Enables Tenant-Wide Takeover

Introduction A high-severity security flaw in Windows Admin Center’s Azure Single Sign-On implementation has revealed how weaknesses in identity token validation can undermine isolation across entire Azure tenants. The vulnerability allows attackers to pivot from a single compromised virtual machine into broader Azure environments, bypassing expected trust boundaries. Background and Discovery The issue was uncovered […]

Cyber attack

Google Cloud Email Feature Exploited in Sophisticated Multi-Stage Phishing Campaign

Introduction Cybersecurity researchers have uncovered a highly sophisticated phishing operation that abuses legitimate cloud automation features within Google Cloud to distribute large-scale phishing emails. By leveraging trusted Google-owned infrastructure, threat actors were able to evade traditional email security controls and deliver convincing lures directly to user inboxes. Background and Context According to findings disclosed by […]