Azure Service Tags tagged as security risk, Microsoft disagrees
ID: 7ad82c5e-e62c-5b9f-a816-3506b7a3987f
STIX ID: report--7ad82c5e-e62c-5b9f-a816-3506b7a3987f
Feed Name: Bleeping Computer
Tenable disclosed a high-severity issue in Azure Service Tags that allows attackers to craft SSRF-like requests (abusing Application Insights availability tests and custom headers) to bypass firewall rules and access internal services and APIs across multiple Azure services; Tenable recommends adding authentication/authorization layers because Microsoft does not plan to patch and views Service Tags as a routing mechanism rather than a security boundary, and Microsoft states it has seen no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
