Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant’s identity and access others’ data, credentials, and cloud workloads.
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Origine de l’article : lire l’article original





