×
Profile

mbgsec

Breaking AI agents, hacking, citizen development and infosec.
By Michael Bargury 😈 · Over 2 subscribers!
By subscribing, I agree to Terms of Use and Information Collection Notice recieving nerdy emails from Michael
No thanks >
  • Skip to primary navigation
  • Skip to content
  • Skip to footer
Michael Bargury Michael Bargury
  • Talks
  • WIP
  • Weblog
  • About
    Michael Bargury

    Michael Bargury

    Security research, hacking, AppSec, primarily focused on AI agents.

    • X
    • BlueSky
    • GitHub
    • LinkedIn
    • RSS

    Rogue Azure AD Guests Can Steal Data via Power Apps

    less than 1 minute read

    A few default guest setting manipulations in Azure AD and over-promiscuous low-code app developer connections can upend data protections.

    Direct Link

    Updated: July 14, 2023

    Share on

    X Facebook LinkedIn Bluesky
    Previous Next

    You May Also Enjoy

    First Public Confirmation of Threat Actors Targeting AI Systems

    4 minute read

    Over the past year I’ve been asking people the same question over and over again: when our AI systems are targeted, will you know?

    Make Real Progress In Security From AI

    1 minute read

    I gave a talk at the AI Agent Security Summit by Zenity Labs on October 8th in San Francisco. I’ll post a blog version of that talk here shortly.

    How Should AI Ask for Our Input?

    2 minute read

    Enterprise systems provide a terrible user experience. That’s common knowledge. Check out one of the flash keynotes about the latest flagship AI product by ...

    Pwn the Enterprise - thank you AI! Slides, Demos and Techniques

    6 minute read

    We’re getting asks for more info about the 0click AI exploits we dropped this week at DEFCON / BHUSA. We gave a talk at BlackHat, but it’ll take time bef...

    • Twitter
    • Weblog Feed
    • Feed
    © 2026 Michael Bargury. Powered by Jekyll & Minimal Mistakes.