Microsoft patches Bing vulnerability allowing data snooping and search result manipulation.

TL;DR Summary
A vulnerability in Microsoft's Bing search engine was discovered earlier this year that allowed users to alter search results and access other Bing users' private information from Teams, Outlook, and Office 365. The vulnerability was detected in the Azure Active Directory (AAD) identity and access management service, and over 1,000 apps and websites on Microsoft's cloud were discovered with similar misconfiguration exploits. The exploit was patched on February 2nd, just days before Microsoft launched Bing's AI-powered Chat feature.
- Microsoft exploit could control Bing search results and Office 365 data The Verge
- Microsoft Patched Bing Vulnerability That Allowed Snooping on Email and Other Data - WSJ The Wall Street Journal
- Microsoft patched Bing vulnerability that allowed snooping on email and other data Fox Business
- Security Researcher Hacks into Microsoft Bing to Change Search Results to His Liking MySmartPrice
- Microsoft Fixes Missing Data In Bing Webmaster Tools API Search Engine Roundtable
Reading Insights
Total Reads
0
Unique Readers
8
Time Saved
3 min
vs 3 min read
Condensed
87%
585 → 78 words
Want the full story? Read the original article
Read on The Verge