Security · 4h ago
Azure Automation Flaw Could Let Attackers Hijack Cross-Tenant Identities
Microsoft fixed a public-by-default configuration and code flaws in Azure Automation that could allow attackers to seize another tenant's identity. The vulnerabilities could enable access to other tenants' data, credentials, and cloud workloads. Microsoft addressed the issue after responsible disclosure.
Meridian48 take
While Microsoft patched this, the public-by-default setting highlights how cloud misconfigurations remain a low-hanging fruit for attackers.
Read the full reporting
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover →
Dark Reading
azure-automationidentity-takeover