Home / Jul 26, 2026 / Story
0
#5 Dark Reading general July 24, 2026 at 12:48 UTC

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

By Jeffrey Schwartz

AI Summary

Microsoft patched a public-by-default misconfiguration in Azure Automation combined with code-level flaws that could have allowed attackers to perform cross-tenant identity takeover, gaining access to other tenants' data, credentials, and cloud workloads. The issue stemmed from Azure Automation's default configuration exposing managed identity capabilities beyond intended scope. Cloud security teams should audit Azure Automation configurations and managed identity permissions as a priority remediation action.

Relevance score: 82.0/100

# More from July 26