logo

Azure Service Tags tagged as security risk, Microsoft disagrees

ID: 7ad82c5e-e62c-5b9f-a816-3506b7a3987f

STIX ID: report--7ad82c5e-e62c-5b9f-a816-3506b7a3987f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-03

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Tenable disclosed a high-severity issue in Azure Service Tags that allows attackers to craft SSRF-like requests (abusing Application Insights availability tests and custom headers) to bypass firewall rules and access internal services and APIs across multiple Azure services; Tenable recommends adding authentication/authorization layers because Microsoft does not plan to patch and views Service Tags as a routing mechanism rather than a security boundary, and Microsoft states it has seen no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.