Newsletter
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

Real Hacker Staff by Real Hacker Staff
September 19, 2023
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Sep 19, 2023THNKnowledge Security / Cybersecurity

Microsoft on Monday mentioned it took steps to right a evident safety gaffe that led to the publicity of 38 terabytes of personal information.

The leak was found on the corporate’s AI GitHub repository and is claimed to have been inadvertently made public when publishing a bucket of open-source coaching information, Wiz mentioned. It additionally included a disk backup of two former workers’ workstations containing secrets and techniques, keys, passwords, and over 30,000 inside Groups messages.

The repository, named “robust-models-transfer,” is not accessible. Previous to its takedown, it featured supply code and machine studying fashions pertaining to a 2020 analysis paper titled “Do Adversarially Strong ImageNet Fashions Switch Higher?”

“The publicity got here as the results of a very permissive SAS token – an Azure characteristic that enables customers to share information in a fashion that’s each onerous to trace and onerous to revoke,” Wiz mentioned in a report. The difficulty was reported to Microsoft on June 22, 2023.

Cybersecurity

Particularly, the repository’s README.md file instructed builders to obtain the fashions from an Azure Storage URL that unintentionally additionally granted entry to all the storage account, thereby exposing extra personal information.

“Along with the overly permissive entry scope, the token was additionally misconfigured to permit “full management” permissions as an alternative of read-only,” Wiz researchers Hillai Ben-Sasson and Ronny Greenberg mentioned. “Which means, not solely may an attacker view all of the information within the storage account, however they might delete and overwrite present information as properly.”

Microsoft AI

In response to the findings, Microsoft mentioned its investigation discovered no proof of unauthorized publicity of buyer information and that “no different inside providers have been put in danger due to this subject.” It additionally emphasised that prospects needn’t take any motion on their half.

The Home windows makers additional famous that it revoked the SAS token and blocked all exterior entry to the storage account. The issue was resolved two after accountable disclosure.

Microsoft AI

To mitigate such dangers going ahead, the corporate has expanded its secret scanning service to incorporate any SAS token which will have overly permissive expirations or privileges. It mentioned it additionally recognized a bug in its scanning system that flagged the precise SAS URL within the repository as a false constructive.

“As a result of lack of safety and governance over Account SAS tokens, they need to be thought of as delicate because the account key itself,” the researchers mentioned. “Subsequently, it’s extremely advisable to keep away from utilizing Account SAS for exterior sharing. Token creation errors can simply go unnoticed and expose delicate information.”

UPCOMING WEBINAR

Id is the New Endpoint: Mastering SaaS Safety within the Fashionable Age

Dive deep into the way forward for SaaS safety with Maor Bin, CEO of Adaptive Defend. Uncover why identification is the brand new endpoint. Safe your spot now.

Supercharge Your Abilities

This isn’t the primary time misconfigured Azure storage accounts have come to mild. In July 2022, JUMPSEC Labs highlighted a situation through which a risk actor may benefit from such accounts to realize entry to an enterprise on-premise atmosphere.

The event is the most recent safety blunder at Microsoft and comes almost two weeks after the corporate revealed that hackers primarily based in China have been in a position to infiltrate the corporate’s programs and steal a extremely delicate signing key by compromising an engineer’s company account and certain accessing an crash dump of the patron signing system.

“AI unlocks enormous potential for tech firms. Nonetheless, as information scientists and engineers race to carry new AI options to manufacturing, the large quantities of knowledge they deal with require extra safety checks and safeguards,” Wiz CTO and co-founder Ami Luttwak mentioned in an announcement.

“This rising know-how requires massive units of knowledge to coach on. With many improvement groups needing to govern large quantities of knowledge, share it with their friends or collaborate on public open-source initiatives, instances like Microsoft’s are more and more onerous to watch and keep away from.”

Discovered this text fascinating? Comply with us on Twitter  and LinkedIn to learn extra unique content material we submit.





Source link

Related articles

Google releases new YouTube Create app: a mobile video editing app for content creators

Google releases new YouTube Create app: a mobile video editing app for content creators

September 22, 2023
Studio Bot expands to 170+ international markets!

Studio Bot expands to 170+ international markets!

September 21, 2023
Tags: AccidentallyConfidentialDataExposeMicrosoftresearchersTerabytes
Share76Tweet47

Related Posts

Google releases new YouTube Create app: a mobile video editing app for content creators

Google releases new YouTube Create app: a mobile video editing app for content creators

by Real Hacker Staff
September 22, 2023
0

Google has launched a brand new video modifying app known as YouTube Create app on the Google Play Retailer geared toward...

Studio Bot expands to 170+ international markets!

Studio Bot expands to 170+ international markets!

by Real Hacker Staff
September 21, 2023
0

Apple Updates Keynote, Pages, Numbers for iOS/iPadOS 17

by Real Hacker Staff
September 21, 2023
0

Right here’s what’s new in Pages 13.2: • Deliver new dimension to your paperwork with 3D objects in USDZ format•...

Mysterious ‘Sandman’ Threat Actor Targets Telecom Providers Across Three Continents

Mysterious ‘Sandman’ Threat Actor Targets Telecom Providers Across Three Continents

by Real Hacker Staff
September 22, 2023
0

Sep 21, 2023THNTelecom Safety / Cyber Assault A beforehand undocumented risk actor dubbed Sandman has been attributed to a set...

Best iPhone 15 Plus screen protectors

Best iPhone 15 Plus screen protectors

by Real Hacker Staff
September 21, 2023
0

You are going to love the newest iPhone, particularly with the additional display actual property you are getting with the...

Load More
  • Trending
  • Comments
  • Latest

OPPO’s European journey takes another hit as it ceases distribution in France

July 27, 2023

vivo Y11 (2023) unveiled with Helio P35 SoC and 5,000 mAh battery

April 1, 2023

US seizes Z-Library login domain, but secret URLs for each user remain active

May 5, 2023

How to change the audio output on Android

June 11, 2023

SmallRig P200 Bi-Color LED Light Panel

0

Pinterest brings shopping capabilities to Shuffles, its collage-making app

0

Microsoft Ends $1 Xbox Game Pass Offer For First Month of Use

0

Apple shows off upcoming mixed-reality headset to its top execs

0
China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

September 22, 2023
Plantiga Technologies’ AI-powered footwear sensor pod aims to reduce injury risks

Plantiga Technologies’ AI-powered footwear sensor pod aims to reduce injury risks

September 22, 2023
Nintendo Expands Switch Online’s Game Boy Advance Library Next Week

Nintendo Expands Switch Online’s Game Boy Advance Library Next Week

September 22, 2023
Russia-Ukraine war: List of key events, day 576 | Russia-Ukraine war News

Russia-Ukraine war: List of key events, day 576 | Russia-Ukraine war News

September 22, 2023

Recent News

China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

China reiterates ceasefire, peace talks ‘only way’ to end Ukraine war | Politics News

September 22, 2023
Plantiga Technologies’ AI-powered footwear sensor pod aims to reduce injury risks

Plantiga Technologies’ AI-powered footwear sensor pod aims to reduce injury risks

September 22, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
    • CAMERA
  • COMPUTERS
    • LAPTOP
    • APPLICATIONS
    • AUDIO
  • WRITE FOR US
  • Advertise Here

© 2003 Real Hacker News