CyberDom Blog

Exploiting Azure IMDS

On my way to another vulnerability (which was submitted to MSRC), I found vast misconfigurations and abuses in Azure IMDS.

What do you call a scenario where nothing is broken, yet everything is exposed? A bug, an abuse, or a Read the rest

Inside Entra Agent ID

Inside Entra Agent ID

Think of Entra Agent ID like a passport for an AI worker. The agent can move between systems, call tools, and act on behalf of users, but it should never travel without a clear identity, a defined route, and a … Read the rest

Entra ID User App Config Abuse

When you hunt for vulnerabilities long enough, you keep tripping over abuses hiding in plain sight. Some have been quietly farmed for years while others spill out of fresh features and rushed integrations. This piece lives in that messy middle, … Read the rest

Weaponizing Exchange Online Inbox Rules

Exchange Online’s split architecture creates blind spots that BEC operators have been quietly exploiting. This post walks through four distinct techniques for creating inbox rules that evade standard detection surfaces, then examines the evasion combinations that leave most SIEM stacks … Read the rest

Harvest Now Decrypt Later

Harvest Now, Decrypt Later, or Decrypt Later, Damage Forever… Attackers are already collecting data.

If you work in security long enough, you eventually realize that most “future threats” are simply today’s threats with better marketing. Quantum computing is a perfect … Read the rest