Microsoft patched this JWT flaw back in July. A public proof-of-concept turned it into real attacks in under 48 hours — here's exactly what's broken…
My read
Aliteq
a researcher posted SharePoint exploit code on Tuesday. attackers were forging admin access by Thursday