By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
CableFree TVCableFree TVCableFree TV
  • Home
  • News
    • Sports
    • Tech
    • Politics
  • Entertainment
  • Blog
    • Sponsored
  • Privacy Policy
  • Terms of Service
  • About Us
  • Contact
Search
  • Advertise
Reading: Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
Share
Sign In
Notification Show More
Aa
CableFree TVCableFree TV
Aa
  • Home
  • News
  • Entertainment
  • Blog
  • Privacy Policy
  • Terms of Service
  • About Us
  • Contact
Search
  • Home
  • News
    • Sports
    • Tech
    • Politics
  • Entertainment
  • Blog
    • Sponsored
  • Privacy Policy
  • Terms of Service
  • About Us
  • Contact
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
CableFree TV > Blog > News > Tech > Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
Tech

Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

admin
Last updated: 2023/09/18 at 1:16 PM
admin
Share
3 Min Read
SHARE


Microsoft AI researchers accidentally exposed tens of terabytes of sensitive data, including private keys and passwords, while publishing a storage bucket of open-source training data on GitHub.

In research shared with TechCrunch, cloud security startup Wiz said it discovered a GitHub repository belonging to Microsoft’s AI research division as part of its ongoing work into the accidental exposure of cloud-hosted data.

Readers of the GitHub repository, which provided open source code and AI models for image recognition, were instructed to download the models from an Azure Storage URL. However, Wiz found that this URL was configured to grant permissions on the entire storage account, exposing additional private data by mistake.

This data included 38 terabytes of sensitive information, including the personal backups of two Microsoft employees’ personal computers. The data also contained other sensitive personal data, including passwords to Microsoft services, secret keys, and over 30,000 internal Microsoft Teams messages from hundreds of Microsoft employees.

The URL, which had exposed this data since 2020, was also misconfigured to allow “full control” rather than “read-only” permissions, according to Wiz, which meant anyone who knew where to look could potentially delete, replace, and inject malicious content into them.

Wiz notes that the storage account wasn’t directly exposed. Rather, the Microsoft AI developers included an overly permissive shared access signature (SAS) token in the URL. SAS tokens are a mechanism used by Azure that allows users to create shareable links granting access to an Azure Storage account’s data.

“AI unlocks huge potential for tech companies,” Wiz co-founder and CTO Ami Luttwak told TechCrunch. “However, as data scientists and engineers race to bring new AI solutions to production, the massive amounts of data they handle require additional security checks and safeguards. With many development teams needing to manipulate massive amounts of data, share it with their peers or collaborate on public open-source projects, cases like Microsoft’s are increasingly hard to monitor and avoid.”

Wiz said it shared its findings with Microsoft on June 22, and Microsoft revoked the SAS token two days later on June 24. Microsoft said it completed its investigation on potential organizational impact on August 16.

In a blog post shared with TechCrunch before publication, Microsoft’s Security Response Center said that “no customer data was exposed, and no other internal services were put at risk because of this issue.”

Microsoft said that as a result of Wiz’s research, it has expanded GitHub’s secret spanning service, which monitors all public open-source code changes for plaintext exposure of credentials and other secrets to include any SAS token that may have overly permissive expirations or privileges.



Source link

https://cablefreetv.org

You Might Also Like

Amazon to invest up to $4 billion in AI startup Anthropic

Correcto grabs $7M to build out its ‘Grammarly for Spanish’

California governor vetoes bill to ban driverless AV trucks

A conversation with Cruise’s Kyle Vogt, Bird scoops up Spin, and self-driving trucks live to see another day in Cali

Building an equitable cap table puts more tools in a startup’s toolbox

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
admin September 18, 2023 September 18, 2023
Share This Article
Facebook Twitter Copy Link Print
Share
Previous Article Without Single Training Session And Proper Rest, India Face Formidable China In Football Opener
Next Article “Kick To The Rear End Not The Worst Thing”: Sri Lanka Coach Chris Silverwood
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

India vs Australia – “Don’t Throw Your Wicket Away…”: Virender Sehwag’s Advice To Shubman Gill Despite Ton In 2nd ODI
Sports September 25, 2023
American-Made Abrams Tanks Arrive in Ukraine, U.S. Officials Say
News September 25, 2023
“A Proud Moment”: Shooter Aishwary Pratap Singh Tomar On His Double-Win At Asian Games
Sports September 25, 2023
Sri Lanka Medical Panel Head Gives Big Update On Wanindu Hasaranga’s Injury
Sports September 25, 2023
//

We Provide Up-to-date News Articles by collecting them from around the world.

Quick Link

  • Home
  • News
    • Sports
    • Tech
    • Politics
  • Entertainment
  • Blog
    • Sponsored
  • Privacy Policy
  • Terms of Service
  • About Us
  • Contact

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form id=”847″]

CableFree TVCableFree TV
Follow US
© 2020-2023 CableFree TV. All Rights Reserved.
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

[mc4wp_form]
Zero spam, Unsubscribe at any time.
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Register Lost your password?