Microsoft AI researchers accidentally leaked 38 terabytes of confidential company data — all because of one misconfigured permission token.
According to Wiz, the mistake was made when Microsoft AI researchers were attempting to publish a "bucket of open-source training material" and "AI models for image recognition" to the developer platform.
The researchers miswrote the files' accompanying SAS token, or the storage URL that establishes file permissions. Basically, instead of granting GitHub users access to the downloadable AI material specifically, the butchered token allowed general access to the entire storage account. And we're not just talking read-only permissions. The mistake actually granted "full control" access, meaning that anyone who might have wanted to tinker with the many terabytes of data — including that of the AI training material and AI models included in the pile — would have been able to.
An "attacker could have injected malicious code into all the AI models in this storage account," Wiz's researchers write, "and every user who trusts Microsoft’s GitHub repository would've been infected by it.", meaning that this sensitive material has basically been open-season for several years.
Norge Siste Nytt, Norge Overskrifter
Similar News:Du kan også lese nyheter som ligner på denne som vi har samlet inn fra andre nyhetskilder.
Galaxy Buds FE pricing tipped; Samsung leaks user manualSamsung leaks the user manual for its unannounced Galaxy Buds FE and a tipster reveals the price.
Les mer »
Microsoft accidentally leaked 38TB of data, but the company says no customer data was exposed.Cloud security researchers at Wiz found the leak and reported it to Microsoft. Here’s what was leaked, according to Microsoft (with its emphasis):
Les mer »
Latest Pixel 8 Pro Leaks Reveal Google’s Exciting DecisionsGoogle's Pixel 8 Pro is set to redefine what a modern smartphone can deliver.
Les mer »
The Vampiric Vanity Project That Accidentally Became a Watershed Moment in HorrorHow A24 harkens back to the Surrealist greats of the 1930s.
Les mer »
Oops: Trump Accidentally Blew Up His January 6 Legal Defense on National TVJack Smith’s job just got significantly easier.
Les mer »
Microsoft just accidentally released 38TB of private dataMicrosoft’s own AI researchers accidentally leaked 38TB of highly sensitive data on their own GitHub page, potentially creating a field day for hackers.
Les mer »