• Latest
  • Trending
  • All
  • News
  • BUSINESS
  • SCIENCE
  • LIFESTYLE
  • TECH
Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

September 18, 2023

Indulge in Opulence: Punctual’s Exquisite Stretch Limousines

September 22, 2023
Requiem for a Forgotten West Texas Cow Town

Requiem for a Forgotten West Texas Cow Town

September 22, 2023
Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

September 22, 2023
Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

September 22, 2023
How We Paid Off $28,000 Of Debt In 15 Months

How We Paid Off $28,000 Of Debt In 15 Months

September 22, 2023
Where to Watch & Stream Online

Where to Watch & Stream Online

September 22, 2023
Sessions to Hold Hearing with U.S. Postmaster General on Postal … – House Committee on Oversight and Reform |

Press Release | Press Releases | Newsroom | U.S. Senator Bill … – Senator Bill Cassidy

September 20, 2023
USA TODAY HSS Super 25 schedule week of Sept. 18

USA TODAY HSS Super 25 schedule week of Sept. 18

September 20, 2023
Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

September 20, 2023
Buffalo Chicken Mac and Cheese

Buffalo Chicken Mac and Cheese

September 20, 2023
Suspended UMC Latina bishop accused of financial malfeasance and retaliation

Suspended UMC Latina bishop accused of financial malfeasance and retaliation

September 20, 2023

[4K] CENTURY CITY – Walking Tour of Century City Mall, West Los Angeles, USA – 4K UHD

September 20, 2023
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
No Result
View All Result
Home TECH

Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

by Minnesota Digital News
September 18, 2023
in TECH
0
Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Microsoft AI researchers accidentally exposed tens of terabytes of sensitive data, including private keys and passwords, while publishing a storage bucket of open-source training data on GitHub.

In research shared with TechCrunch, cloud security startup Wiz said it discovered a GitHub repository belonging to Microsoft’s AI research division as part of its ongoing work into the accidental exposure of cloud-hosted data.

Readers of the GitHub repository, which provided open source code and AI models for image recognition, were instructed to download the models from an Azure Storage URL. However, Wiz found that this URL was configured to grant permissions on the entire storage account, exposing additional private data by mistake.

This data included 38 terabytes of sensitive information, including the personal backups of two Microsoft employees’ personal computers. The data also contained other sensitive personal data, including passwords to Microsoft services, secret keys, and over 30,000 internal Microsoft Teams messages from hundreds of Microsoft employees.

The URL, which had exposed this data since 2020, was also misconfigured to allow “full control” rather than “read-only” permissions, according to Wiz, which meant anyone who knew where to look could potentially delete, replace, and inject malicious content into them.

Wiz notes that the storage account wasn’t directly exposed. Rather, the Microsoft AI developers included an overly permissive shared access signature (SAS) token in the URL. SAS tokens are a mechanism used by Azure that allows users to create shareable links granting access to an Azure Storage account’s data.

“AI unlocks huge potential for tech companies,” Wiz co-founder and CTO Ami Luttwak told TechCrunch. “However, as data scientists and engineers race to bring new AI solutions to production, the massive amounts of data they handle require additional security checks and safeguards. With many development teams needing to manipulate massive amounts of data, share it with their peers or collaborate on public open-source projects, cases like Microsoft’s are increasingly hard to monitor and avoid.”

Wiz said it shared its findings with Microsoft on June 22, and Microsoft revoked the SAS token two days later on June 24. Microsoft said it completed its investigation on potential organizational impact on August 16.

In a blog post shared with TechCrunch before publication, Microsoft’s Security Response Center said that “no customer data was exposed, and no other internal services were put at risk because of this issue.”

Microsoft said that as a result of Wiz’s research, it has expanded GitHub’s secret spanning service, which monitors all public open-source code changes for plaintext exposure of credentials and other secrets to include any SAS token that may have overly permissive expirations or privileges.



Source link

Share196Tweet123Share49
Minnesota Digital News

Minnesota Digital News

Saint Paul
◉
75°
Cloudy
6:21 am8:09 pm CDT
Feels like: 75°F
Wind: 9mph ESE
Humidity: 72%
Pressure: 30.19"Hg
UV index: 1
TueWedThuFri
100/79°F
97/72°F
90/68°F
84/61°F
Weather forecast Saint Paul, Minnesota ▸
TRAVEL

Indulge in Opulence: Punctual’s Exquisite Stretch Limousines

by Minnesota Digital News
September 22, 2023
Requiem for a Forgotten West Texas Cow Town
HISTORY

Requiem for a Forgotten West Texas Cow Town

by Minnesota Digital News
September 22, 2023
Zendaya Sets the Record Straight on Tom Holland Engagement Rumors
ENTERTAINMENT

Zendaya Sets the Record Straight on Tom Holland Engagement Rumors

by Minnesota Digital News
September 22, 2023
Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface
GADGET

Engadget Podcast: iPhone 15 Pro reviews, Microsoft picks AI over Surface

by Minnesota Digital News
September 22, 2023
How We Paid Off $28,000 Of Debt In 15 Months
FINANCE

How We Paid Off $28,000 Of Debt In 15 Months

by Minnesota Digital News
September 22, 2023
Where to Watch & Stream Online
MOVIE

Where to Watch & Stream Online

by Minnesota Digital News
September 22, 2023
Sessions to Hold Hearing with U.S. Postmaster General on Postal … – House Committee on Oversight and Reform |
PRESS RELEASE

Press Release | Press Releases | Newsroom | U.S. Senator Bill … – Senator Bill Cassidy

by Minnesota Digital News
September 20, 2023
USA TODAY HSS Super 25 schedule week of Sept. 18
SPORTS

USA TODAY HSS Super 25 schedule week of Sept. 18

by Minnesota Digital News
September 20, 2023
Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!
FASHION

Check Out These 5 Fall Plus Size Shopping Tips to Help You Shop with Confidence!

by Minnesota Digital News
September 20, 2023
Buffalo Chicken Mac and Cheese
FOOD

Buffalo Chicken Mac and Cheese

by Minnesota Digital News
September 20, 2023
Suspended UMC Latina bishop accused of financial malfeasance and retaliation
Religion

Suspended UMC Latina bishop accused of financial malfeasance and retaliation

by Minnesota Digital News
September 20, 2023
Shopping

[4K] CENTURY CITY – Walking Tour of Century City Mall, West Los Angeles, USA – 4K UHD

by Minnesota Digital News
September 20, 2023
Broadcom Stock Sees Another Big Insider Buy
BUSINESS

Broadcom Stock Sees Another Big Insider Buy

by Minnesota Digital News
September 20, 2023
A Pair of Sun Probes Just Got Closer to Solving a Solar Enigma
SCIENCE

A Pair of Sun Probes Just Got Closer to Solving a Solar Enigma

by Minnesota Digital News
September 20, 2023
10 Real Estate Deals in 18 Months After Losing 80% of His Income
REAL ESTATE

10 Real Estate Deals in 18 Months After Losing 80% of His Income

by Minnesota Digital News
September 20, 2023
10 Companies That Hire for Remote Admin Jobs
MONEY

10 Companies That Hire for Remote Admin Jobs

by Minnesota Digital News
September 20, 2023
Steelcase expects ‘significantly improved’ profit, as more employees return to offices
MARKET

Steelcase expects ‘significantly improved’ profit, as more employees return to offices

by Minnesota Digital News
September 20, 2023
USA VeeraSimhaReddy premier Fans Firstday theaters SLOGAN OF THE DAYYYY…..#JAIBALAYYA #Chicago
ARTS & THEATER

USA VeeraSimhaReddy premier Fans Firstday theaters SLOGAN OF THE DAYYYY…..#JAIBALAYYA #Chicago

by Minnesota Digital News
September 20, 2023
The Silly Story Behind The Weirdest Xbox Exclusive
GAMING

The Silly Story Behind The Weirdest Xbox Exclusive

by Minnesota Digital News
September 20, 2023
Minnesota Digital News

Copyright © 2023 Minnesota Digital News

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Copyright Notice
  • Anti Spam Policy
  • Medical Disclaimer
  • DMCA Compliance
  • Terms and Conditions
  • Social Media Disclaimer
  • Amazon Affiliate disclaimer

Follow Us

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

Copyright © 2023 Minnesota Digital News