A newly discovered vulnerability, dubbed “G-Door,” allows malicious actors to circumvent Microsoft 365 security measures by exploiting unmanaged Google Docs accounts. This security flaw poses a significant threat to organizations relying on Microsoft 365’s Conditional Access (CA) policies for protection.
According to Potsolutions the G-Door vulnerability stems from the ability to create personal or workspace Google accounts using a company’s domain name. These unmanaged accounts can then access third-party applications, bypassing Microsoft 365’s security controls.
2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide
Users can easily create personal Google accounts or sign up for the free Google Docs Essentials Starter plan using their company email addresses.
This process requires no administrative approval and can be completed in minutes, giving users an unmanaged Google identity associated with the organization’s domain, reads the report.
The G-Door vulnerability undermines several key security features of Microsoft 365:
To protect against the G-Door vulnerability, organizations should:
As organizations increasingly rely on cloud-based productivity suites, addressing vulnerabilities like G-Door becomes crucial for maintaining a robust security posture. IT administrators and security professionals must remain vigilant and adapt their strategies to protect against these emerging threats.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…