Skip Navigation
Hacker News @lemmy.smeargle.fans

Microsoft employees exposed internal passwords in security lapse

techcrunch.com

Microsoft employees exposed internal passwords in security lapse | TechCrunch

1 comments
  • This is the best summary I could come up with:


    Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with SOCRadar, a cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s Azure cloud service that was storing internal information relating to Microsoft’s Bing search engine.

    The Azure storage server housed code, scripts and configuration files containing passwords, keys and credentials used by the Microsoft employees for accessing other internal databases and systems.

    Yoleri told TechCrunch that the exposed data could potentially help malicious actors identify or access other places where Microsoft stores its internal files.

    Identifying those storage locations “could result in more significant data leaks and possibly compromise the services in use,” Yoleri said.

    In a similar security lapse last year, researchers found that Microsoft employees were exposing their own corporate network logins in code published to GitHub.

    An independent board of cyber experts tasked with investigating the email breach wrote in their report, published last week, that the hackers succeeded because of a “cascade of security failures at Microsoft.”


    The original article contains 383 words, the summary contains 170 words. Saved 56%. I'm a bot and I'm open source!