CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

38TB of data accidentally exposed by Microsoft AI researchers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1681

As cited

Copy frozen at (site build).

cloud saas

38TB of data accidentally exposed by Microsoft AI researchers

Wiz Research discovered a misconfigured shared access signature (SAS) token in Microsoft's AI GitHub repository that exposed approximately 38 terabytes of data, including over 30,000 internal Microsoft Teams messages. The exposure occurred through improper configuration rather than an active security breach. Microsoft secured the repository following the disclosure.

Why it matters: Organizations using GitHub and cloud storage must audit service account tokens and access credentials in code repositories, as misconfigured SAS tokens and similar authentication mechanisms commonly leak sensitive internal communications and proprietary data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

38TB of data accidentally exposed by Microsoft AI researchers

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

38TB of data accidentally exposed by Microsoft AI researchers

Wiz Research discovered a misconfigured shared access signature (SAS) token in Microsoft's artificial intelligence (AI) GitHub repository that exposed 38 terabytes of data. The leaked material included more than 30,000 internal Microsoft Teams messages and other sensitive information. Microsoft addressed the exposure after Wiz's responsible disclosure.

Why it matters: Organizations using GitHub and cloud storage should audit SAS token permissions and access controls, as a single misconfigured credential can expose massive volumes of internal communications and proprietary data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

38TB of data accidentally exposed by Microsoft AI researchers

Wiz Research discovered a misconfigured shared access signature (SAS) token in Microsoft's artificial intelligence (AI) GitHub repository that exposed 38 terabytes of data. The leaked material included more than 30,000 internal Microsoft Teams messages and other sensitive information. Microsoft addressed the exposure after Wiz's responsible disclosure.

Why it matters: Organizations using GitHub and cloud storage should audit SAS token permissions and access controls, as a single misconfigured credential can expose massive volumes of internal communications and proprietary data.

VendorsMicrosoftGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary