As cited
Copy frozen at (site build).
cloud saas
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft patched a publicly enabled default configuration and code vulnerabilities in Azure Automation that could have allowed attackers to hijack identities across tenants and access other organizations' data, credentials, and workloads. The issue stemmed from overly permissive default settings combined with multiple code flaws in the platform.
Why it matters: Azure Automation users face identity hijacking and cross-tenant lateral movement risk; teams should review tenant configurations and access controls to ensure Automation accounts are not exposed.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft patched a publicly enabled default configuration and code vulnerabilities in Azure Automation that could have allowed attackers to hijack identities across tenants and access other organizations' data, credentials, and workloads. The issue stemmed from overly permissive default settings combined with multiple code flaws in the platform.
Why it matters: Azure Automation users face identity hijacking and cross-tenant lateral movement risk; teams should review tenant configurations and access controls to ensure Automation accounts are not exposed.
- Source published
- First seen by Cybersecurity Tracker