Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Microsoft patches Azure Automation flaw enabling cross-tenant identity takeover

Microsoft has remediated a configuration vulnerability in Azure Automation that allowed unauthorized access to cross-tenant identities and data. The flaw stemmed from a public-by-default setting combined with code execution vulnerabilities, posing a significant risk to multi-tenant cloud environments. It remains unclear if the vulnerability was exploited in the wild prior to the patch.

Dark Readingabout 4 hours agoUSCredibility 55%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.6
Source

Part of 2 situations

Related signals

8 found