On my way to another vulnerability (which was submitted to MSRC), I found vast misconfigurations and abuses in Azure IMDS. What do you call a scenario where nothing is broken, yet everything is exposed? A bug, an abuse, or a Read the rest The post Exploiting Azure IMDS appeared first on CYBERDOM .
Think of Entra Agent ID like a passport for an AI worker. The agent can move between systems, call tools, and act on behalf of users, but it should never travel without a clear identity, a defined route, and a Read the rest The post Inside Entra Agent ID appeared first on CYBERDOM .
When you hunt for vulnerabilities long enough, you keep tripping over abuses hiding in plain sight. Some have been quietly farmed for years while others spill out of fresh features and rushed integrations. This piece lives in that messy middle, Read the rest The post Entra ID User App Config Abuse appeared first on CYBERDOM .
We’re in 2026, and inbox persistence is still here, and it’s one of the core pillars of the Microsoft 365 attack playbook. Once an attacker lands in a mailbox, they don’t rush to chase noisy privilege escalation. They go for Read the rest The post From ESTS Cookie Replay to Inbox Persistence appeared first on CYBERDOM .
Exchange Online’s split architecture creates blind spots that BEC operators have been quietly exploiting. This post walks through four distinct techniques for creating inbox rules that evade standard detection surfaces, then examines the evasion combinations that leave most SIEM stacks Read the rest The post Weaponizing Exchange Online Inbox Rules appeared first on CYBERDOM .
Harvest Now, Decrypt Later, or Decrypt Later, Damage Forever Attackers are already collecting data. If you work in security long enough, you eventually realize that most “future threats” are simply today’s threats with better marketing. Quantum computing is a perfect Read the rest The post Harvest Now Decrypt Later appeared first on CYBERDOM .
Web browsers quietly handle credentials, tokens, and sensitive data for every tab we open, turning the browser into a critical security boundary. When that trust line cracks, even slightly, the impact can reach far beyond a single session or machine. Read the rest The post Microsoft Edge Heap Memory Exposure (MemEdge) appeared first on CYBERDOM .
I love middleware, if it s on Cloud Vendor, AI components, etc. This time is the AI Desktop Middleware. As you remember, in the old days, AI was merely a guest in a browser, maybe locked securely within a browser sandbox Read the rest The post The AI Middleware Risks in Claude Desktop appeared first on CYBERDOM .
You know the drill. A major alert lands, and within minutes, your screen is drowning in browser tabs, multiple consoles, stale queries that return nothing useful, and half-written notes scattered across random text files named something like “incident-final-09.txt.” That kind Read the rest The post Sentinel MCP for Threat Hunting and Investigations appeared first on CYBERDOM .
A Deep-Dive into Microsoft Foundry Guardrails, Adversarial Prompt Attacks, and Runtime LLM Defense. Part 1. Embedding LLMs into production workloads without a runtime defense layer is the same architectural mistake as deploying internet-facing applications without a WAF. The attack surface Read the rest The post Securing AI at the Gate appeared first on CYBERDOM .