Credential Theft via Misconfigured Spring Boot Actuator Leads to SharePoint Data Exfiltration
Article Content
- •Attackers exploited a misconfigured Spring Boot Actuator endpoint to steal credentials.
- •The OAuth2 ROPC flow was used to bypass MFA and access SharePoint data.
- •Sensitive application secrets were stored in plaintext, exacerbating the breach.
In a recent cybersecurity incident, attackers exploited an exposed Spring Boot Actuator endpoint to harvest credentials from leaked configuration data. They utilized the OAuth2 Resource Owner Password Credentials (ROPC) flow to authenticate without multi-factor authentication (MFA), compromising a SharePoint service account. The attackers accessed sensitive information, including configuration details related to SharePoint integration, which were revealed through the unsecured /configprops endpoint. Although no plaintext credentials were directly exposed, the attackers gained valuable reconnaissance that facilitated their access. Analysts discovered that sensitive secrets for an internal application were stored in plaintext within a spreadsheet, further aiding the attackers. This incident underscores the risks associated with poor credential management and misconfigurations in cloud environments. The targeted organization experienced data exfiltration from SharePoint Online as a result of these vulnerabilities. The current status of the incident is under investigation, with recommendations for securing exposed endpoints and improving credential storage practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…