Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads.
Read full story at Dark Reading →