The SaaS RootKit: A New Attack Vector for Hidden Forwarding Rules in O365


Posted on in Presentations

Researchers detected a new SaaS vulnerability within Microsoft’s OAuth application registration. Through this vulnerability, anyone can leverage Exchange’s legacy API to create hidden forwarding rules in O365 mailboxes. This talk will demo the OAuth registration process in Microsoft as well as the use of the new vulnerability.

Access this and other Conference presentations with your free RSAC Membership. Your Membership also includes AI-powered summaries, mind maps, and slides for Conference presentations, Group Discussions with peers and experts, and more.

Go Now >>
Participants
Maor Bin

Speaker

CEO, Adaptive Shield


Share With Your Community