Untitled attachment
https://cyberplace.social/system/media_attachments/files/111/823/766/882/496/840/original/0980e4eb08d80640.png
Not mentioned in the blog - to grant Oauth access to read all mailboxes (as happened here), you need to be the tenant admin. There's not a vuln being used here, as Microsoft would have mentioned it for sure - so somebody made a pretty big config error in production to allow a test tenant app to be used to grant *checks notes* reading of any mailbox.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.