logo

38TB of data accidentally exposed by Microsoft AI researchers

ID: f306b4e8-a76c-527d-80c4-6f6bbd6d91e2

STIX ID: report--f306b4e8-a76c-527d-80c4-6f6bbd6d91e2

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2023-09-18

Date Updated: 2026-05-01

...
...

**Executive summary:** Wiz Research discovered that a Microsoft AI research GitHub repository published an Azure Account SAS token with excessive scope and full-control permissions, exposing ~38 TB of private data—including workstation backups containing secrets, private keys, passwords, and 30,000+ internal Teams messages—and creating significant supply-chain and persistence risks because the token was long-lived and model files (TensorFlow ckpt using pickle) could enable remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.