nOAuth-ing to see here. [Research Saturday] episode artwork

EPISODE · Aug 2, 2025 · 23 MIN

nOAuth-ing to see here. [Research Saturday]

from CyberWire Daily · host N2K Networks

This week, we are joined by Eric Woodruff, Chief Identity Architect at Semperis, discussing "nOAuth Abuse Alert: Full Account Takeover of Entra Cross-Tenant SaaS Applications". Semperis researchers identified a critical authentication flaw known as nOAuth in 9 out of 104 tested SaaS applications integrated with Microsoft Entra ID. This low-complexity but severe vulnerability allows attackers with just a user’s email address and access to an Entra tenant to impersonate users, exfiltrate data, and move laterally within affected apps—with no viable defense or detection available to customers. The findings spotlight ongoing risks tied to improper use of email claims in authentication and emphasize the urgent need for SaaS vendors to adopt secure OpenID Connect practices and remediate vulnerable applications. Complete our annual ⁠audience survey⁠ before August 31. The research can be found here: nOAuth Abuse Alert: Full Account Takeover of Entra Cross-Tenant SaaS Applications

Episode metadata supplied by the publisher feed · Published Aug 2, 2025

Embed this episode

NOW PLAYING

nOAuth-ing to see here. [Research Saturday]

0:00 23:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CyberWire Daily?

This episode is 23 minutes long.

When was this CyberWire Daily episode published?

This episode was published on August 2, 2025.

Can I download this CyberWire Daily episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!