Sunday, October 1, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Microsoft Cloud: Another critical vulnerability – sharp criticism of Microsoft

Eliza Houghton by Eliza Houghton
August 8, 2023
in World
0
Microsoft Cloud: Another critical vulnerability – sharp criticism of Microsoft
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

“Extremely irresponsible” is how Amit Yoran, CEO of the security company Tenable, describes Microsoft’s behavior when it comes to security. The background is that his company found and reported a critical vulnerability in the Microsoft Azure Cloud more than three months ago. It was only after Tenable spoke publicly about this problem that Microsoft closed it almost overnight in a hasty action.

Advertisement

In his LinkedIn posting “Microsoft…The Truth Is Even Worse Than You Think”, Yoran really pulled off the leather and also made a connection with the events surrounding the recently stolen master key:

‘Microsoft’s lack of visibility into intrusions, irresponsible security practices and vulnerabilities that expose all of their customers to risks they are intentionally left in the dark about.
…
What you hear from Microsoft is “just trust us,” but what you get back is very little transparency and a toxic culture of obfuscation. Given this pattern of behavior, how can a CISO, board of directors, or executive team believe that Microsoft will do the right thing?’

Password theft possible

The new vulnerability gave attackers access to cloud credentials such as tokens or passwords under certain conditions. A first update from Microsoft did not completely eliminate the problem. The cloud company then announced a fix for September 28, which prompted Tenable to make the problem public, but without giving any details about the vulnerability.

A short time later Microsoft reported completion; ITwire quoted a Microsoft press spokesman as quoting the gap for most of the affected customers who were already closed in June and now all customers are protected. Further customer actions are not required. I guess that’s what Yoran meant when he said, “Just trust us.” Tenable has since published a more detailed description of the vulnerability: Unauthorized Access to Cross-Tenant Applications in Microsoft Power Platform.

Update 08/04/2023 11:27 am

The vulnerability is not in Azure Active Directory (AAD), but consists of unauthorized access to the Azure API. Among other things, OAuth client IDs and secrets, which are typically located in the AAD, could also be tapped via this. We have removed incorrect or misleading references to the Azure Active Directory.

(yeah)

Zur Startseite

#Microsoft #Cloud #critical #vulnerability #sharp #criticism #Microsoft

Tags: Azure ADCloudCloud ComputingcriticalcriticismMicrosoftMicrosoft Azuresharpvulnerability
Previous Post

Niger | West African regional bloc ultimatum expires

Next Post

A primitive without an owner, a traveling retiree and police expertise: the plot of a 4.7 million prize

Eliza Houghton

Eliza Houghton

Related Posts

Real Madrid does not give Barcelona a chance and takes the Clásico at home (86-79)
World

Real Madrid does not give Barcelona a chance and takes the Clásico at home (86-79)

by Eliza Houghton
October 1, 2023
El Palmer also wins the second derby in the City of Palma
World

El Palmer also wins the second derby in the City of Palma

by Eliza Houghton
October 1, 2023
Dani Rodrik: “We need a multipolar world: neither a hegemony of the United States nor a confrontation with China”
World

Dani Rodrik: “We need a multipolar world: neither a hegemony of the United States nor a confrontation with China”

by Eliza Houghton
October 1, 2023
Atlético de Madrid – Cádiz, live: result, goals and minute by minute of the EA Sports League match today
World

Atlético de Madrid – Cádiz, live: result, goals and minute by minute of the EA Sports League match today

by Eliza Houghton
October 1, 2023
Nagorno Karabakh |  Protests continue and prayers begin
World

Nagorno Karabakh | Protests continue and prayers begin

by Eliza Houghton
October 1, 2023
Next Post
A primitive without an owner, a traveling retiree and police expertise: the plot of a 4.7 million prize

A primitive without an owner, a traveling retiree and police expertise: the plot of a 4.7 million prize

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

La Liga, live |  Barrenetxea leads Real Sociedad against Real Madrid at the Santiago Bernabéu

La Liga, live | Barrenetxea leads Real Sociedad against Real Madrid at the Santiago Bernabéu

September 17, 2023
Josu Ternera admits in the Évole documentary his involvement in an amnestied murder

Josu Ternera admits in the Évole documentary his involvement in an amnestied murder

September 14, 2023
UNESCO calls for government regulation of the use of AI in schools

UNESCO calls for government regulation of the use of AI in schools

September 9, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

amnesty Apple Artificial Intelligence attack attacks China Court data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Pro Rubiales Russia Russia-Ukraine invasion Security Software development Spain Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

amnesty Apple Artificial Intelligence attack attacks China Court data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Pro Rubiales Russia Russia-Ukraine invasion Security Software development Spain Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years

Recent Posts

  • Real Madrid does not give Barcelona a chance and takes the Clásico at home (86-79)
  • El Palmer also wins the second derby in the City of Palma
  • Dani Rodrik: “We need a multipolar world: neither a hegemony of the United States nor a confrontation with China”
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.