Nathan McNulty@NathanMcNultySince everyone is sharing MSRC stories 🙃 I had a PrivEsc from User Admin, a role many give helpdesk or HR, to Global Admin MSRC: Not a vulnerability, requires a built-in Microsoft app in the tenant to exploit Also MSRC: It's a vulnerability when someone else submits it🤷♂️Opens with an observation
Nathan McNulty@NathanMcNulty😭 VS Code extensions are no different than browser extensions - high risk that you should be controlling with an allowlist Yes, review and approval processes suck, but IR sucks even more t.coOpens with an observation