LIVE · cybersecurity feed
Live wire
security

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet.&#;x26;#;xc2;&#;x26;#;xa0; &#;x26;#;xc2;&#;x26;#;xa0;It allows you to Get and Set info from/to M365, Entra Users and Entra

zeroday.news ·

A recent report highlights the utility of Microsoft Graph and PowerShell for information gathering within Microsoft 365 and Entra environments, specifically focusing on the identification of stale accounts and licenses. The report suggests that while Microsoft Graph is a relatively mature API, having reached version 2.3.9, its adoption by many users and commercial tools may not yet be widespread.

Microsoft Graph serves as a unified API designed to supersede several older interfaces, offering capabilities to retrieve and modify information across various Microsoft services. In the context of this report, its application for querying Microsoft 365 and Entra ID (formerly Azure Active Directory) users and their associated attributes is emphasized. This functionality is particularly relevant for administrative tasks and security auditing.

The mechanism described involves leveraging PowerShell scripts to interact with the Microsoft Graph API. PowerShell provides a robust scripting environment for automating administrative tasks within Windows and Microsoft cloud ecosystems. By crafting specific Graph API calls through PowerShell, administrators or malicious actors can programmatically extract data related to user accounts, their status, and assigned licenses.

The focus on "stale accounts and licenses" points to a common security and operational challenge. Stale accounts, often those belonging to former employees or inactive users, can pose a security risk if not properly deprovisioned, potentially serving as lingering access points. Similarly, unmanaged or stale licenses represent unnecessary expenditure and can complicate license management.

While the report does not specify a vulnerability, it outlines a legitimate administrative capability that could be misused. The ability to programmatically enumerate and identify inactive resources is a standard function for IT administrators seeking to maintain a clean and secure environment. However, if an unauthorized entity gains access to credentials with sufficient permissions, they could leverage these same techniques to map out an organization's user base and identify potential targets or misconfigurations.

Mitigation for such information gathering typically involves robust access controls, ensuring that only authorized personnel have the necessary permissions to query sensitive directory information. Implementing the principle of least privilege, multi-factor authentication, and regular auditing of administrative accounts are standard practices. Furthermore, organizations should have established processes for identifying and deactivating stale accounts and reclaiming unused licenses to reduce both security exposure and operational overhead.

This type of reporting underscores the ongoing importance of understanding the capabilities of administrative tools and APIs within complex enterprise environments. As cloud platforms evolve and consolidate their interfaces, the potential for both efficient administration and sophisticated information gathering, whether benign or malicious, increases. Organizations must remain vigilant in securing their administrative interfaces and continuously audit access to critical directory services.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.

malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been discovered in NASA/JPL's open-source AIT-GUI software, which is used to control spacecraft instruments. The flaw allows unauthenticated attackers to execute arbitrary commands, run server-side scripts, and manipulate command sequences by exploiting a lack of authentication, session checks, and CSRF protection. Researchers confirmed the issue, which has a CVSS score of 9.4, and a fix is available in version 2.5.2.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.