×
This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

As businesses around the world have shifted their digital infrastructure over the last decade from self-hosted servers to the cloud, they’ve benefitted from the standardized, built-in security features of major cloud providers like Microsoft. But with so much riding on these systems, there can be potentially disastrous consequences at a massive scale if something goes wrong. Case in point: Security researcher Dirk-jan Mollema recently stumbled upon a pair of vulnerabilities in Microsoft Azure’s identity and access management platform that could have been exploited for a potentially cataclysmic takeover of all Azure customer accounts.

Known as Entra ID, the system stores each Azure cloud customer’s user identities, sign-in access controls, applications, and subscription management tools. Mollema has studied Entra ID security in depth and published multiple studies about weaknesses in the system, which was formerly known as Azure Active Directory. But while preparing to present at the Black Hat security conference in Las Vegas in July, Mollema discovered two vulnerabilities that he realized could be used to gain global administrator privileges—essentially god mode—and compromise every Entra ID directory, or what is known as a “tenant.” Mollema says that this would have exposed nearly every Entra ID tenant in the world other than, perhaps, government cloud infrastructure.

“I was just staring at my screen. I was like, ‘No, this shouldn’’t really happen,’” says Mollema, who runs the Dutch cybersecurity company Outsider Security and specializes in cloud security. “It was quite bad. As bad as it gets, I would say.”

“From my own tenants—my test tenant or even a trial tenant—you could request these tokens and you could impersonate basically anybody else in anybody else’s tenant,” Mollema adds. “That means you could modify other people’s configuration, create new and admin users in that tenant, and do anything you would like.”

Given the seriousness of the vulnerability, Mollema disclosed his findings to the Microsoft Security Response Center on July 14, the same day that he discovered the flaws. Microsoft started investigating the findings that day and issued a fix globally on July 17. The company confirmed to Mollema that the issue was fixed by July 23 and implemented extra measures in August. Microsoft issued a CVE for the vulnerability on September 4.

“We mitigated the newly identified issue quickly, and accelerated the remediation work underway to decommission this legacy protocol usage, as part of our Secure Future Initiative,” Tom Gallagher, Microsoft’s Security Response Center vice president of engineering, told WIRED in a statement. “We implemented a code change within the vulnerable validation logic, tested the fix, and applied it across our cloud ecosystem.”

Gallagher says that Microsoft found “no evidence of abuse” of the vulnerability during its investigation.

Both vulnerabilities relate to legacy systems still functioning within Entra ID. The first involves a type of Azure authentication token Mollema discovered known as Actor Tokens that are issued by an obscure Azure mechanism called the “Access Control Service.” Actor Tokens have some special system properties that Mollema realized could be useful to an attacker when combined with another vulnerability. The other bug was a major flaw in a historic Azure Active Directory application programming interface known as “Graph” that was used to facilitate access to data stored in Microsoft 365. Microsoft is in the process of retiring Azure Active Directory Graph and transitioning users to its successor, Microsoft Graph, which is designed for Entra ID. The flaw was related to a failure by Azure AD Graph to properly validate which Azure tenant was making an access request, which could be manipulated so the API would accept an Actor Token from a different tenant that should have been rejected.

Source link
#Microsoft #Entra #Vulnerability #Catastrophic

Today’s Wordle answer should be easy to solve if you’re not a fan of big cities.

If you just want to be told today’s word, you can jump to the bottom of this article for today’s Wordle solution revealed. But if you’d rather solve it yourself, keep reading for some clues, tips, and strategies to assist you.

Where did Wordle come from?

Originally created by engineer Josh Wardle as a gift for his partner, Wordle rapidly spread to become an international phenomenon, with thousands of people around the globe playing every day. Alternate Wordle versions created by fans also sprang up, including battle royale Squabble, music identification game Heardle, and variations like Dordle and Quordle that make you guess multiple words at once

Wordle eventually became so popular that it was purchased by the New York Times, and TikTok creators even livestream themselves playing.

What’s the best Wordle starting word?

The best Wordle starting word is the one that speaks to you. But if you prefer to be strategic in your approach, we have a few ideas to help you pick a word that might help you find the solution faster. One tip is to select a word that includes at least two different vowels, plus some common consonants like S, T, R, or N.

What happened to the Wordle archive?

The entire archive of past Wordle puzzles was originally available for anyone to enjoy whenever they felt like it, but it was later taken down, with the website’s creator stating it was done at the request of the New York Times. However, the New York Times then rolled out its own Wordle Archive, available only to NYT Games subscribers.

Is Wordle getting harder?

It might feel like Wordle is getting harder, but it actually isn’t any more difficult than when it first began. You can turn on Wordle‘s Hard Mode if you’re after more of a challenge, though.

Here’s a subtle hint for today’s Wordle answer:

Countryside.

Does today’s Wordle answer have a double letter?

The letter R appears twice.

Mashable 101 Fan Fave: Nominate your favorite creators today

Today’s Wordle is a 5-letter word that starts with…

Today’s Wordle starts with the letter R.

The Wordle answer today is…

Get your last guesses in now, because it’s your final chance to solve today’s Wordle before we reveal the solution.

Drumroll please!

The solution to today’s Wordle is…

RURAL

Don’t feel down if you didn’t manage to guess it this time. There will be a new Wordle for you to stretch your brain with tomorrow, and we’ll be back again to guide you with more helpful hints. Are you also playing NYT Strands? See hints and answers for today’s Strands.

Reporting by Chance Townsend, Caitlin Welsh, Sam Haysom, Amanda Yeo, Shannon Connellan, Cecily Mauran, Mike Pearl, and Adam Rosenberg contributed to this article.

If you’re looking for more puzzles, Mashable’s got games now! Check out our games hub for Mahjong, Sudoku, free crossword, and more.

Not the day you’re after? Here’s the solution to yesterday’s Wordle.

#Wordle #today #answer #hints #April">Wordle today: The answer and hints for April 29, 2026
                                            
                                                            Today’s Wordle answer should be easy to solve if you’re not a fan of big cities.If you just want to be told today’s word, you can jump to the bottom of this article for today’s Wordle solution revealed. But if you’d rather solve it yourself, keep reading for some clues, tips, and strategies to assist you.
        SEE ALSO:
        
            Mahjong, Sudoku, free crossword, and more: Play games on Mashable
            
        
    

        SEE ALSO:
        
            NYT Connections hints today: Clues, answers for April 29, 2026
            
        
    
Where did Wordle come from?Originally created by engineer Josh Wardle as a gift for his partner, Wordle rapidly spread to become an international phenomenon, with thousands of people around the globe playing every day. Alternate Wordle versions created by fans also sprang up, including battle royale Squabble, music identification game Heardle, and variations like Dordle and Quordle that make you guess multiple words at once. Wordle eventually became so popular that it was purchased by the New York Times, and TikTok creators even livestream themselves playing.What’s the best Wordle starting word?The best Wordle starting word is the one that speaks to you. But if you prefer to be strategic in your approach, we have a few ideas to help you pick a word that might help you find the solution faster. One tip is to select a word that includes at least two different vowels, plus some common consonants like S, T, R, or N.What happened to the Wordle archive?The entire archive of past Wordle puzzles was originally available for anyone to enjoy whenever they felt like it, but it was later taken down, with the website’s creator stating it was done at the request of the New York Times. However, the New York Times then rolled out its own Wordle Archive, available only to NYT Games subscribers. Is Wordle getting harder?It might feel like Wordle is getting harder, but it actually isn’t any more difficult than when it first began. You can turn on Wordle‘s Hard Mode if you’re after more of a challenge, though.
        SEE ALSO:
        
            NYT Pips hints, answers for April 29, 2026
            
        
    
Here’s a subtle hint for today’s Wordle answer:Countryside.
        
            Mashable Top Stories
        
        
    
Does today’s Wordle answer have a double letter?The letter R appears twice.Mashable 101 Fan Fave: Nominate your favorite creators todayToday’s Wordle is a 5-letter word that starts with…Today’s Wordle starts with the letter R.
        SEE ALSO:
        
            Wordle-obsessed? These are the best word games to play IRL.
            
        
    
The Wordle answer today is…Get your last guesses in now, because it’s your final chance to solve today’s Wordle before we reveal the solution.Drumroll please!The solution to today’s Wordle is…RURALDon’t feel down if you didn’t manage to guess it this time. There will be a new Wordle for you to stretch your brain with tomorrow, and we’ll be back again to guide you with more helpful hints. Are you also playing NYT Strands? See hints and answers for today’s Strands.Reporting by Chance Townsend, Caitlin Welsh, Sam Haysom, Amanda Yeo, Shannon Connellan, Cecily Mauran, Mike Pearl, and Adam Rosenberg contributed to this article.If you’re looking for more puzzles, Mashable’s got games now! Check out our games hub for Mahjong, Sudoku, free crossword, and more.Not the day you’re after? Here’s the solution to yesterday’s Wordle.

                    
                                            
                            
                        
                                    #Wordle #today #answer #hints #April

Wordle answer should be easy to solve if you’re not a fan of big cities.

If you just want to be told today’s word, you can jump to the bottom of this article for today’s Wordle solution revealed. But if you’d rather solve it yourself, keep reading for some clues, tips, and strategies to assist you.

Where did Wordle come from?

Originally created by engineer Josh Wardle as a gift for his partner, Wordle rapidly spread to become an international phenomenon, with thousands of people around the globe playing every day. Alternate Wordle versions created by fans also sprang up, including battle royale Squabble, music identification game Heardle, and variations like Dordle and Quordle that make you guess multiple words at once

Wordle eventually became so popular that it was purchased by the New York Times, and TikTok creators even livestream themselves playing.

What’s the best Wordle starting word?

The best Wordle starting word is the one that speaks to you. But if you prefer to be strategic in your approach, we have a few ideas to help you pick a word that might help you find the solution faster. One tip is to select a word that includes at least two different vowels, plus some common consonants like S, T, R, or N.

What happened to the Wordle archive?

The entire archive of past Wordle puzzles was originally available for anyone to enjoy whenever they felt like it, but it was later taken down, with the website’s creator stating it was done at the request of the New York Times. However, the New York Times then rolled out its own Wordle Archive, available only to NYT Games subscribers.

Is Wordle getting harder?

It might feel like Wordle is getting harder, but it actually isn’t any more difficult than when it first began. You can turn on Wordle‘s Hard Mode if you’re after more of a challenge, though.

Here’s a subtle hint for today’s Wordle answer:

Countryside.

Does today’s Wordle answer have a double letter?

The letter R appears twice.

Mashable 101 Fan Fave: Nominate your favorite creators today

Today’s Wordle is a 5-letter word that starts with…

Today’s Wordle starts with the letter R.

The Wordle answer today is…

Get your last guesses in now, because it’s your final chance to solve today’s Wordle before we reveal the solution.

Drumroll please!

The solution to today’s Wordle is…

RURAL

Don’t feel down if you didn’t manage to guess it this time. There will be a new Wordle for you to stretch your brain with tomorrow, and we’ll be back again to guide you with more helpful hints. Are you also playing NYT Strands? See hints and answers for today’s Strands.

Reporting by Chance Townsend, Caitlin Welsh, Sam Haysom, Amanda Yeo, Shannon Connellan, Cecily Mauran, Mike Pearl, and Adam Rosenberg contributed to this article.

If you’re looking for more puzzles, Mashable’s got games now! Check out our games hub for Mahjong, Sudoku, free crossword, and more.

Not the day you’re after? Here’s the solution to yesterday’s Wordle.

#Wordle #today #answer #hints #April">Wordle today: The answer and hints for April 29, 2026

Today’s Wordle answer should be easy to solve if you’re not a fan of big cities.

If you just want to be told today’s word, you can jump to the bottom of this article for today’s Wordle solution revealed. But if you’d rather solve it yourself, keep reading for some clues, tips, and strategies to assist you.

Where did Wordle come from?

Originally created by engineer Josh Wardle as a gift for his partner, Wordle rapidly spread to become an international phenomenon, with thousands of people around the globe playing every day. Alternate Wordle versions created by fans also sprang up, including battle royale Squabble, music identification game Heardle, and variations like Dordle and Quordle that make you guess multiple words at once

Wordle eventually became so popular that it was purchased by the New York Times, and TikTok creators even livestream themselves playing.

What’s the best Wordle starting word?

The best Wordle starting word is the one that speaks to you. But if you prefer to be strategic in your approach, we have a few ideas to help you pick a word that might help you find the solution faster. One tip is to select a word that includes at least two different vowels, plus some common consonants like S, T, R, or N.

What happened to the Wordle archive?

The entire archive of past Wordle puzzles was originally available for anyone to enjoy whenever they felt like it, but it was later taken down, with the website’s creator stating it was done at the request of the New York Times. However, the New York Times then rolled out its own Wordle Archive, available only to NYT Games subscribers.

Is Wordle getting harder?

It might feel like Wordle is getting harder, but it actually isn’t any more difficult than when it first began. You can turn on Wordle‘s Hard Mode if you’re after more of a challenge, though.

Here’s a subtle hint for today’s Wordle answer:

Countryside.

Does today’s Wordle answer have a double letter?

The letter R appears twice.

Mashable 101 Fan Fave: Nominate your favorite creators today

Today’s Wordle is a 5-letter word that starts with…

Today’s Wordle starts with the letter R.

The Wordle answer today is…

Get your last guesses in now, because it’s your final chance to solve today’s Wordle before we reveal the solution.

Drumroll please!

The solution to today’s Wordle is…

RURAL

Don’t feel down if you didn’t manage to guess it this time. There will be a new Wordle for you to stretch your brain with tomorrow, and we’ll be back again to guide you with more helpful hints. Are you also playing NYT Strands? See hints and answers for today’s Strands.

Reporting by Chance Townsend, Caitlin Welsh, Sam Haysom, Amanda Yeo, Shannon Connellan, Cecily Mauran, Mike Pearl, and Adam Rosenberg contributed to this article.

If you’re looking for more puzzles, Mashable’s got games now! Check out our games hub for Mahjong, Sudoku, free crossword, and more.

Not the day you’re after? Here’s the solution to yesterday’s Wordle.

#Wordle #today #answer #hints #April
In the days since this year’s White House Correspondents’ Dinner was cut short when shots were fired at the event, there has been a boom of conspiracy theory videos created by people who insist that the entire situation was a false flag operation. These kinds of theories are nothing new, but the way they’re spreading now is a reflection of how reaction video culture is reshaping our social media landscape. And even though the initial chaos around the shooting has started to die down, content creators are still posting about what “really” happened.

There is still much we do not know about Cole Allen, the 31-year-old suspected shooter who allegedly traveled from Los Angeles to Washington, DC, ahead of the WCHD and was staying in the same Hilton where the event was held. But that has not stopped content creators from flooding platforms like YouTube, TikTok, Instagram, and X with videos purporting to have more insightful takes on the situation than what’s being reported by the mainstream media.

None of these videos reveal anything that hasn’t already been reported out via traditional media outlets. But each of them speaks to the way that this brand of content has become a normal part of people’s media consumption habits and something that creators see as a viable way to capture attention. In the US, trust in traditional media outlets is at a historic low and more people are turning to social media to stay informed about world events. And that shift has given conspiracy-minded content creators a choice opportunity to influence the way people understand reality.

All of this is similar to what happened in 2024 when Donald Trump survived an assassination attempt while campaigning for the presidency. Then, creators rushed to capitalize on the event while also writing it off as a false flag designed to garner sympathy for the Republican nominee. That news cycle and subsequent discourse dragged on for weeks, both because it was a significant moment in an election year and because it was difficult to understand how Trump could have been shot in his ear without sustaining any visible damage afterward.

Many of the newer videos about the WHCD shooting suggest that we should look at these events as a response to the Trump administration’s propensity for spreading misinformation. And while there is no evidence to suggest that the WHCD shooting was, in fact, orchestrated with Trump’s approval, one could argue the administration is at least partially responsible for the way that this idea has gained traction across the internet.

As easy as it is to laugh at the constant barrage of shitposts coming out of the president’s social media accounts and other official governmental channels, they have undoubtedly had an impact on the way that the public thinks about the current administration. By sharing ugly, immature memes and AI-generated images of Trump as a Christlike figure, the White House has told people that nothing is to be taken seriously and everything can be turned into a crude joke. And at a time when all of the internet’s biggest social media platforms have begun encouraging their users to upload videos of themselves while chasing engagement, it makes sense that many would see this past weekend’s shooting as a chance to boost their profiles.

Trump has made nonsensical “jokes” a significant part of his political brand, and people are responding with very similar energy.

#primetime #conspiracy #theorist #video #creatorsCreators,Instagram,Meta,Streaming,Tech,TikTok,YouTube">It’s primetime for conspiracy theorist video creatorsIn the days since this year’s White House Correspondents’ Dinner was cut short when shots were fired at the event, there has been a boom of conspiracy theory videos created by people who insist that the entire situation was a false flag operation. These kinds of theories are nothing new, but the way they’re spreading now is a reflection of how reaction video culture is reshaping our social media landscape. And even though the initial chaos around the shooting has started to die down, content creators are still posting about what “really” happened.There is still much we do not know about Cole Allen, the 31-year-old suspected shooter who allegedly traveled from Los Angeles to Washington, DC, ahead of the WCHD and was staying in the same Hilton where the event was held. But that has not stopped content creators from flooding platforms like YouTube, TikTok, Instagram, and X with videos purporting to have more insightful takes on the situation than what’s being reported by the mainstream media.None of these videos reveal anything that hasn’t already been reported out via traditional media outlets. But each of them speaks to the way that this brand of content has become a normal part of people’s media consumption habits and something that creators see as a viable way to capture attention. In the US, trust in traditional media outlets is at a historic low and more people are turning to social media to stay informed about world events. And that shift has given conspiracy-minded content creators a choice opportunity to influence the way people understand reality.All of this is similar to what happened in 2024 when Donald Trump survived an assassination attempt while campaigning for the presidency. Then, creators rushed to capitalize on the event while also writing it off as a false flag designed to garner sympathy for the Republican nominee. That news cycle and subsequent discourse dragged on for weeks, both because it was a significant moment in an election year and because it was difficult to understand how Trump could have been shot in his ear without sustaining any visible damage afterward.Many of the newer videos about the WHCD shooting suggest that we should look at these events as a response to the Trump administration’s propensity for spreading misinformation. And while there is no evidence to suggest that the WHCD shooting was, in fact, orchestrated with Trump’s approval, one could argue the administration is at least partially responsible for the way that this idea has gained traction across the internet.As easy as it is to laugh at the constant barrage of shitposts coming out of the president’s social media accounts and other official governmental channels, they have undoubtedly had an impact on the way that the public thinks about the current administration. By sharing ugly, immature memes and AI-generated images of Trump as a Christlike figure, the White House has told people that nothing is to be taken seriously and everything can be turned into a crude joke. And at a time when all of the internet’s biggest social media platforms have begun encouraging their users to upload videos of themselves while chasing engagement, it makes sense that many would see this past weekend’s shooting as a chance to boost their profiles.Trump has made nonsensical “jokes” a significant part of his political brand, and people are responding with very similar energy.#primetime #conspiracy #theorist #video #creatorsCreators,Instagram,Meta,Streaming,Tech,TikTok,YouTube

when shots were fired at the event, there has been a boom of conspiracy theory videos created by people who insist that the entire situation was a false flag operation. These kinds of theories are nothing new, but the way they’re spreading now is a reflection of how reaction video culture is reshaping our social media landscape. And even though the initial chaos around the shooting has started to die down, content creators are still posting about what “really” happened.

There is still much we do not know about Cole Allen, the 31-year-old suspected shooter who allegedly traveled from Los Angeles to Washington, DC, ahead of the WCHD and was staying in the same Hilton where the event was held. But that has not stopped content creators from flooding platforms like YouTube, TikTok, Instagram, and X with videos purporting to have more insightful takes on the situation than what’s being reported by the mainstream media.

None of these videos reveal anything that hasn’t already been reported out via traditional media outlets. But each of them speaks to the way that this brand of content has become a normal part of people’s media consumption habits and something that creators see as a viable way to capture attention. In the US, trust in traditional media outlets is at a historic low and more people are turning to social media to stay informed about world events. And that shift has given conspiracy-minded content creators a choice opportunity to influence the way people understand reality.

All of this is similar to what happened in 2024 when Donald Trump survived an assassination attempt while campaigning for the presidency. Then, creators rushed to capitalize on the event while also writing it off as a false flag designed to garner sympathy for the Republican nominee. That news cycle and subsequent discourse dragged on for weeks, both because it was a significant moment in an election year and because it was difficult to understand how Trump could have been shot in his ear without sustaining any visible damage afterward.

Many of the newer videos about the WHCD shooting suggest that we should look at these events as a response to the Trump administration’s propensity for spreading misinformation. And while there is no evidence to suggest that the WHCD shooting was, in fact, orchestrated with Trump’s approval, one could argue the administration is at least partially responsible for the way that this idea has gained traction across the internet.

As easy as it is to laugh at the constant barrage of shitposts coming out of the president’s social media accounts and other official governmental channels, they have undoubtedly had an impact on the way that the public thinks about the current administration. By sharing ugly, immature memes and AI-generated images of Trump as a Christlike figure, the White House has told people that nothing is to be taken seriously and everything can be turned into a crude joke. And at a time when all of the internet’s biggest social media platforms have begun encouraging their users to upload videos of themselves while chasing engagement, it makes sense that many would see this past weekend’s shooting as a chance to boost their profiles.

Trump has made nonsensical “jokes” a significant part of his political brand, and people are responding with very similar energy.

#primetime #conspiracy #theorist #video #creatorsCreators,Instagram,Meta,Streaming,Tech,TikTok,YouTube">It’s primetime for conspiracy theorist video creators

In the days since this year’s White House Correspondents’ Dinner was cut short when shots were fired at the event, there has been a boom of conspiracy theory videos created by people who insist that the entire situation was a false flag operation. These kinds of theories are nothing new, but the way they’re spreading now is a reflection of how reaction video culture is reshaping our social media landscape. And even though the initial chaos around the shooting has started to die down, content creators are still posting about what “really” happened.

There is still much we do not know about Cole Allen, the 31-year-old suspected shooter who allegedly traveled from Los Angeles to Washington, DC, ahead of the WCHD and was staying in the same Hilton where the event was held. But that has not stopped content creators from flooding platforms like YouTube, TikTok, Instagram, and X with videos purporting to have more insightful takes on the situation than what’s being reported by the mainstream media.

None of these videos reveal anything that hasn’t already been reported out via traditional media outlets. But each of them speaks to the way that this brand of content has become a normal part of people’s media consumption habits and something that creators see as a viable way to capture attention. In the US, trust in traditional media outlets is at a historic low and more people are turning to social media to stay informed about world events. And that shift has given conspiracy-minded content creators a choice opportunity to influence the way people understand reality.

All of this is similar to what happened in 2024 when Donald Trump survived an assassination attempt while campaigning for the presidency. Then, creators rushed to capitalize on the event while also writing it off as a false flag designed to garner sympathy for the Republican nominee. That news cycle and subsequent discourse dragged on for weeks, both because it was a significant moment in an election year and because it was difficult to understand how Trump could have been shot in his ear without sustaining any visible damage afterward.

Many of the newer videos about the WHCD shooting suggest that we should look at these events as a response to the Trump administration’s propensity for spreading misinformation. And while there is no evidence to suggest that the WHCD shooting was, in fact, orchestrated with Trump’s approval, one could argue the administration is at least partially responsible for the way that this idea has gained traction across the internet.

As easy as it is to laugh at the constant barrage of shitposts coming out of the president’s social media accounts and other official governmental channels, they have undoubtedly had an impact on the way that the public thinks about the current administration. By sharing ugly, immature memes and AI-generated images of Trump as a Christlike figure, the White House has told people that nothing is to be taken seriously and everything can be turned into a crude joke. And at a time when all of the internet’s biggest social media platforms have begun encouraging their users to upload videos of themselves while chasing engagement, it makes sense that many would see this past weekend’s shooting as a chance to boost their profiles.

Trump has made nonsensical “jokes” a significant part of his political brand, and people are responding with very similar energy.

#primetime #conspiracy #theorist #video #creatorsCreators,Instagram,Meta,Streaming,Tech,TikTok,YouTube

Post Comment