Microsoft’s own AI researchers accidentally leaked 38TB of highly sensitive data on their own GitHub page, potentially creating a field day for hackers.
It’s just been revealed that Microsoft researchers accidentally leaked 38TB of confidential information onto the company’s GitHub page, where potentially anyone could see it. Among the data trove was a backup of two former employees’ workstations, which contained keys, passwords, secrets, and more than 30,000 private Teams messages.
Data breaches can come from all kinds of sources, but it will be particularly embarrassing for Microsoft that this one originated with its own AI researchers. The Wiz reports states that Microsoft uploaded the data using Shared Access Signature tokens, an Azure feature, that lets users share data through Azure Storage accounts.
Full control It gets worse. The access token that allowed all this was misconfigured to provide full control permissions, Wiz reported, rather than more restrictive read-only permissions. In practice, that meant that anyone who visited the URL could delete and overwrite the files they found, not merely view them.
Yet because it was open to manipulation thanks to its wrongly configured permissions, “an attacker could have injected malicious code into all the AI models in this storage account, and every user who trusts Microsoft’s GitHub repository would’ve been infected by it,” Wiz explains.
South Africa Latest News, South Africa Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Microsoft accidentally leaked 38TB of data, but the company says no customer data was exposed.Cloud security researchers at Wiz found the leak and reported it to Microsoft. Here’s what was leaked, according to Microsoft (with its emphasis):
Read more »
Microsoft AI researchers mistakenly leaked 38TB of company dataA Microsoft AI research team that uploaded training data on GitHub in an effort to offer other researchers open-source code and AI models for image recognition inadvertently exposed 38TB of personal data.
Read more »
Windows leader Panos Panay is leaving MicrosoftA Microsoft Surface and AI event is scheduled for Thursday morning.
Read more »
Get Microsoft Office for Windows or Mac for just $29.97Level up your home office with Office!
Read more »
Microsoft is planning to stream PC cloud games, internal emails revealMicrosoft was turning to Azure for PC game streaming.
Read more »
This is how Microsoft reacted to Sony’s PS5 announcement and price hikeA rare insight into Xbox and PlayStation competition.
Read more »