Microsoft fixes ‘AutoWarp’ Azure bug that exposed customer data
By MYBRANDBOOK
Microsoft has addressed a vulnerability in the Azure Automation service, dubbed as ‘AutoWarp’, that could have allowed attackers to take complete control over other Azure customers' data. The vulnerability allows an attacker to steal other Azure customers' Managed Identities authentication tokens from an internal server that manages the sandboxes of other users.
Microsoft fixed the security flaw by blocking access to auth tokens to all sandboxes except the one that had legitimate access. The company notified all affected Azure Automation service customers and recommended following the security best practices.
Azure Automation accounts impacted by this vulnerability include those with the Managed Identity feature enabled. The company publicly disclosed the vulnerability, saying that it found no evidence that Managed Identities tokens were misused, or AutoWarp exploited in attacks.
Orca Security's Cloud Security Researcher, who discovered the bug, said, “Someone with malicious intentions could've continuously grabbed tokens, and with each token, widen the attack to more Azure customers. This attack could mean full control over resources and data belonging to the targeted account, depending on the permissions assigned by the customer. We discovered large companies at risk (including a global telecommunications company, two car manufacturers, a banking conglomerate, big four accounting firms, and more).
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
AMARA RAJA POWER SYSTEMS LTD.
FIRE BOLTT
VEHERE INTERACTIVE PVT. LTD.
TATA CONSULTANCY SERVICES
Icons Of India : Arjun Malhotra
Arjun Malhotra, the Chairman of Magic Software Inc., is widely recogni...
Icons Of India : Dr. Sanjay Bahl
Dr. Sanjay Bahl has around four decades of experience in the ICT indus...
Icons Of India : Deepak Sharma
Deepak Sharma spearheads Schneider Electric India. He brings with him ...
DRDO - Defence Research and Development Organisation
DRDO responsible for the development of technology for use by the mili...
GeM - Government e Marketplace
GeM is to facilitate the procurement of goods and services by various ...
BSE - Bombay Stock Exchange
The Bombay Stock Exchange (BSE) is one of India’s largest and oldest...
Indian Tech Talent Excelling The Tech World - Thomas Kurian, CEO- Google Cloud
Thomas Kurian, the CEO of Google Cloud, has been instrumental in expan...
Indian Tech Talent Excelling The Tech World - AJAY BANGA, President - World Bank
Ajay Banga is an Indian-born American business executive who currently...
Indian Tech Talent Excelling The Tech World - ANJALI SUD, CEO – Tubi
Anjali Sud, the former CEO of Vimeo, now leads Tubi, Fox Corporation...