logo

Azure Fabric Backdoor With A Twist

ID: 27bbfa06-bb20-50c5-b1c8-463d838ecca1

STIX ID: report--27bbfa06-bb20-50c5-b1c8-463d838ecca1

Feed Name: NCC Research

Threat Score
50/100

Date Published: 2025-10-21

Date Updated: 2026-08-03

...
...

Azure Fabric PoC describes how an attacker can abuse Fabric notebooks and the Activator event engine to delay and trigger execution of Python code that uses the Azure Python SDK to create service principals, a user-assigned managed identity, a virtual machine with a public IP and an NSG allowing SSH from the Internet. The report includes full proof-of-concept code, notes on traces left (notebook run history, package uploads, Entra ID logs), prerequisites (Contributor/Owner permissions or a service principal), and recommended hardening (blocking internet access, private links, workspace outbound access protection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.