Microsoft: 38 TB of data accidentally exposed

Microsoft: 38 TB of data accidentally exposed - Image by Mudassar Iqbal on Pixabay

Share post

The security provider Wiz found 38 TB of data including 30.000 internal Teams messages while browsing Microsoft's AI GitHub repository. According to Wiz, a SAS token misconfigured by the AI ​​research team triggered the issue.

According to the Wiz Research Team, Microsoft's AI research team made a few glaring mistakes when publishing open source training data on GitHub. Apparently, when publishing data, a total of 38 terabytes of data was accidentally marked for publication and then published. Among them: private data, a hard drive backup of two employees' workstations.

38 TBytes of data including tokens, passwords and keys

The team accidentally published a backup containing sensitive data, private keys, passwords and over 30.000 internal Microsoft Teams messages. The researchers shared their files using an Azure feature called SAS tokens, which allows you to share data from Azure storage accounts. The access level can only be limited to certain files; However, in this case, the link was configured to share the entire storage account - including an additional 38TB of private files.

This is how the data was discovered

As part of the Wiz research team's ongoing work, the team is studying data hosted in the cloud. Incorrectly configured storage containers can often be found. In this case, the team found a GitHub repository under the Microsoft organization called robust-models-transfer. The repository is part of Microsoft's AI research division and is used to provide open source code and AI models for image recognition.

Readers of the repository were instructed to download the models from an Azure Storage URL. The Wiz team simply called up this URL once. However, this URL allowed access to more than just open source models. A misconfiguration allowed access not only to the open source models, but to the entire storage account. The private data was then accidentally disclosed. A subsequent scan showed that this account contained 38 TB of additional data - including Microsoft employees' PC backups. The backups contained sensitive personal data, including passwords to Microsoft services, secret keys and over 30.000 internal Microsoft Teams messages from 359 Microsoft employees.

The Wiz team describes a further detailed description of the misconfiguration and its consequences in its detailed blog post.

More at WIZ.io

 


About Wiz

We're reinventing cloud security from the inside out. Led by an experienced and visionary team, our mission is to help companies create secure cloud environments that accelerate their business. By creating a normalizing layer between cloud environments, our platform enables organizations to quickly identify and remediate critical risks.


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more