Points finger at privilege escalation via application rights in Azure AD, which Microsoft says is as designed

Security company Malwarebytes suspects a breach of its Office 365 and Azure tenancies is by the same attacker behind the SolarWinds hack, but reckons flaws in Azure Active Directory security are also to blame.…