The dark art of OIDC abuse - A case study in Entra ID - Cody Burkard - NDC Security 2026

NDC Conferences · 8:58

Cody Burkhardt presents a now-patched Azure DevOps vulnerability in workload-identity-federation service connections: a user-controlled OIDC subject on the “verify and save” path let an attacker impersonate any servic...

Read the full summary on tuber

Redirecting...