Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Watch Kasabian’s Serge Pizzorno join Calvin Harris for ‘Release The Pressure’ at huge Hampden Park shows as DJ celebrates with ‘rave haggis’

    August 3, 2026

    Sam Altman reveals the investing advice billionaire Peter Thiel gave him that’s led to a $3.3 billion net worth

    August 3, 2026

    Treasonous Trump Sides With Iran After Minnesota Was Cyberattacked

    August 3, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
    Technology

    Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

    By AdminSeptember 18, 2023
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Microsoft AI researchers accidentally exposed terabytes of internal sensitive data


    Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

    Microsoft AI researchers accidentally exposed tens of terabytes of sensitive data, including private keys and passwords, while publishing a storage bucket of open-source training data on GitHub.

    In research shared with TechCrunch, cloud security startup Wiz said it discovered a GitHub repository belonging to Microsoft’s AI research division as part of its ongoing work into the accidental exposure of cloud-hosted data.

    Readers of the GitHub repository, which provided open source code and AI models for image recognition, were instructed to download the models from an Azure Storage URL. However, Wiz found that this URL was configured to grant permissions on the entire storage account, exposing additional private data by mistake.

    This data included 38 terabytes of sensitive information, including the personal backups of two Microsoft employees’ personal computers. The data also contained other sensitive personal data, including passwords to Microsoft services, secret keys, and over 30,000 internal Microsoft Teams messages from hundreds of Microsoft employees.

    The URL, which had exposed this data since 2020, was also misconfigured to allow “full control” rather than “read-only” permissions, according to Wiz, which meant anyone who knew where to look could potentially delete, replace, and inject malicious content into them.

    Wiz notes that the storage account wasn’t directly exposed. Rather, the Microsoft AI developers included an overly permissive shared access signature (SAS) token in the URL. SAS tokens are a mechanism used by Azure that allows users to create shareable links granting access to an Azure Storage account’s data.

    “AI unlocks huge potential for tech companies,” Wiz co-founder and CTO Ami Luttwak told TechCrunch. “However, as data scientists and engineers race to bring new AI solutions to production, the massive amounts of data they handle require additional security checks and safeguards. With many development teams needing to manipulate massive amounts of data, share it with their peers or collaborate on public open-source projects, cases like Microsoft’s are increasingly hard to monitor and avoid.”

    Wiz said it shared its findings with Microsoft on June 22, and Microsoft revoked the SAS token two days later on June 24. Microsoft said it completed its investigation on potential organizational impact on August 16.

    In a blog post shared with TechCrunch before publication, Microsoft’s Security Response Center said that “no customer data was exposed, and no other internal services were put at risk because of this issue.”

    Microsoft said that as a result of Wiz’s research, it has expanded GitHub’s secret spanning service, which monitors all public open-source code changes for plaintext exposure of credentials and other secrets to include any SAS token that may have overly permissive expirations or privileges.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleThis Treaty Could Stop Plastic Pollution—or Doom the Earth to Drown in It
    Next Article The Constitution of the United States: Understanding the supreme law of the U.S.

    RELATED POSTS

    Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate

    August 3, 2026

    Best Car Vacuums (2026): Handheld, Cordless, Shopping Tips

    August 3, 2026

    Inside the London hacker house taking a stand against founder burnout

    August 2, 2026

    Best Organic Mattresses (2026): Certified Nontoxic, Natural Sleep

    August 2, 2026

    Apps that help you break free from doomscrolling and get active

    August 1, 2026

    SpaceX’s Falcon 9 Rocket Is About to Crash Into the Moon—and It Could Be Visible From Earth

    August 1, 2026
    latest posts

    Watch Kasabian’s Serge Pizzorno join Calvin Harris for ‘Release The Pressure’ at huge Hampden Park shows as DJ celebrates with ‘rave haggis’

    Calvin Harris brought out Kasabian’s Serge Pizzorno for his two huge homecoming shows at Hampden…

    Sam Altman reveals the investing advice billionaire Peter Thiel gave him that’s led to a $3.3 billion net worth

    August 3, 2026

    Treasonous Trump Sides With Iran After Minnesota Was Cyberattacked

    August 3, 2026

    Todd Blanche confirmation advances after anti-weaponization fund axed

    August 3, 2026

    Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    The Summer Book review – dismally cosy

    August 3, 2026
    Categories
    • Books (1,405)
    • Business (6,309)
    • Events (64)
    • Film (6,245)
    • Lifestyle (4,320)
    • Music (6,368)
    • Politics (6,291)
    • Science (5,662)
    • Technology (6,241)
    • Television (5,935)
    • Uncategorized (9)
    • US News (6,297)
    popular posts

    9 best credit cards of January 2023

    CNN Underscored reviews financial products such as credit cards and bank accounts based on their…

    Paint the Legend: Behind the scenes on The…

    May 15, 2026

    The Most Popular News of the Week

    August 25, 2025

    ‘Jury Duty’ Star James Marsden on Ronald’s Big Reveal & Keeping Antics Comedic

    April 22, 2023
    Archives
    Browse By Category
    • Books (1,405)
    • Business (6,309)
    • Events (64)
    • Film (6,245)
    • Lifestyle (4,320)
    • Music (6,368)
    • Politics (6,291)
    • Science (5,662)
    • Technology (6,241)
    • Television (5,935)
    • Uncategorized (9)
    • US News (6,297)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    The Summer Book review – dismally cosy

    August 3, 2026

    ‘Today’ Announces New Host Joining The Show

    August 3, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT