Skip to main content

Tag: microsoft azure

4 articles

JADEPUFFER Exploits Azure Compromise for Destructive Attacks

JADEPUFFER hackers exploited a compromised Azure account to unleash a wave of destructive attacks, wreaking havoc on sensitive data and services by targeting key areas like Storage Accounts, SQL databases, and Virtual Machines. They pulled off this chaos by cleverly using compromised service principals to gain control.

Analyst 207
Blurred employees walk past server racks in a brightly-lit corporate office or data center interior.

Azure Breach Exposes Millions of Employee Records at Top Firms

A threat actor known as TheHatman is peddling a staggering 1.7 million employee records from McDonald's, along with millions more from other top firms, allegedly stolen from Microsoft Azure environments. The breach, which Hudson Rock deems highly authentic, has left giants like Vodafone, Tata Consultancy Services, and IHG Hotels & Resorts vulnerable.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit cloud data center or server room with ambient lighting.

Azure Flaw Exposes Platform-Wide Key to All Databases

Microsoft patched a vulnerability in Azure Cosmos DB, dubbed CosmosEscape, which exposed a platform-wide key to all databases, but fortunately, no customer data was accessed and no action is required. The flaw was discovered by security firm Wiz, which detailed the exploit chain that could be used to take advantage of the vulnerability.

Analyst 207
Servers in a data center with cables, representing a secure cloud computing environment.

Microsoft Disputes Azure Vulnerability Report, Silent Patch Issued

Security researcher Justin O'Leary claims a critical flaw in Azure Backup for AKS could let users with zero Kubernetes permissions gain full cluster administration, but Microsoft disputes the finding. The tech giant quietly issued a patch without acknowledging the vulnerability.

Analyst 207