HomeTechnologyMicrosoft AI Researchers Accidentally...

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data


Sep 19, 2023THNData Safety / Cybersecurity

Microsoft on Monday said it took steps to correct a glaring security gaffe that led to the exposure of 38 terabytes of private data.

The leak was discovered on the company’s AI GitHub repository and is said to have been inadvertently made public when publishing a bucket of open-source training data, Wiz said. It also included a disk backup of two former employees’ workstations containing secrets, keys, passwords, and over 30,000 internal Teams messages.

The repository, named “robust-models-transfer,” is no longer accessible. Prior to its takedown, it featured source code and machine learning models pertaining to a 2020 research paper titled “Do Adversarially Robust ImageNet Models Transfer Better?”

“The exposure came as the result of an overly permissive SAS token – an Azure feature that allows users to share data in a manner that is both hard to track and hard to revoke,” Wiz said in a report. The issue was reported to Microsoft on June 22, 2023.

Cybersecurity

Specifically, the repository’s README.md file instructed developers to download the models from an Azure Storage URL that accidentally also granted access to the entire storage account, thereby exposing additional private data.

“In addition to the overly permissive access scope, the token was also misconfigured to allow “full control” permissions instead of read-only,” Wiz researchers Hillai Ben-Sasson and Ronny Greenberg said. “Meaning, not only could an attacker view all the files in the storage account, but they could delete and overwrite existing files as well.”

Microsoft AI

In response to the findings, Microsoft said its investigation found no evidence of unauthorized exposure of customer data and that “no other internal services were put at risk because of this issue.” It also emphasized that customers need not take any action on their part.

The Windows makers further noted that it revoked the SAS token and blocked all external access to the storage account. The problem was resolved two after responsible disclosure.

Microsoft AI

To mitigate such risks going forward, the company has expanded its secret scanning service to include any SAS token that may have overly permissive expirations or privileges. It said it also identified a bug in its scanning system that flagged the specific SAS URL in the repository as a false positive.

“Due to the lack of security and governance over Account SAS tokens, they should be considered as sensitive as the account key itself,” the researchers said. “Therefore, it is highly recommended to avoid using Account SAS for external sharing. Token creation mistakes can easily go unnoticed and expose sensitive data.”

UPCOMING WEBINAR

Identity is the New Endpoint: Mastering SaaS Security in the Modern Age

Dive deep into the future of SaaS security with Maor Bin, CEO of Adaptive Shield. Discover why identity is the new endpoint. Secure your spot now.

Supercharge Your Skills

This is not the first time misconfigured Azure storage accounts have come to light. In July 2022, JUMPSEC Labs highlighted a scenario in which a threat actor could take advantage of such accounts to gain access to an enterprise on-premise environment.

The development is the latest security blunder at Microsoft and comes nearly two weeks after the company revealed that hackers based in China were able to infiltrate the company’s systems and steal a highly sensitive signing key by compromising an engineer’s corporate account and likely accessing an crash dump of the consumer signing system.

“AI unlocks huge potential for tech companies. However, as data scientists and engineers race to bring new AI solutions to production, the massive amounts of data they handle require additional security checks and safeguards,” Wiz CTO and co-founder Ami Luttwak said in a statement.

“This emerging technology requires large sets of data to train on. With many development teams needing to manipulate massive amounts of data, share it with their peers or collaborate on public open-source projects, cases like Microsoft’s are increasingly hard to monitor and avoid.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.





Source link

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

Peloton co-founder and Chief Product Officer Tom Cortese is leaving the company

Peloton co-founder and Chief Product Officer Tom Cortese is leaving...

NFL Week 4 injury tracker: Will Jones, Watson and Montgomery play Thursday?

ESPN FantasySep 26, 2023, 04:56 PM ET6 Minute ReadESPN's Fantasy...

How the Writers Deal Got Done: Inside the Room

Getty Images; Adobe Stock; THR Illustration On Saturday, Sept. 23, Disney...

Read Now

Judge Finds Trump Inflated Property Values, a Victory for New York A.G.

A New York judge ruled on Tuesday that Donald J. Trump persistently committed fraud by inflating the value of his assets, and stripped the former president of control over some of his signature New York properties.The decision by Justice Arthur F. Engoron is a major victory...

Peloton co-founder and Chief Product Officer Tom Cortese is leaving the company

Peloton co-founder and Chief Product Officer Tom Cortese is leaving the company after nearly 12 years.He'll be replaced by Silicon Valley veteran Nick Caldwell, who previously held positions at Twitter, Google and Microsoft."After nearly 12 years of pouring myself into Peloton and serving our Members, I...

NFL Week 4 injury tracker: Will Jones, Watson and Montgomery play Thursday?

ESPN FantasySep 26, 2023, 04:56 PM ET6 Minute ReadESPN's Fantasy Football Week 4 injury tracker, featuring an aggregation of injury updates for quarterbacks, running backs, wide receivers and tight ends whose teams are scheduled to play this week. Here we'll track practice reports, injury updates and...

How the Writers Deal Got Done: Inside the Room

Getty Images; Adobe Stock; THR Illustration On Saturday, Sept. 23, Disney CEO Bob Iger was in Beverly Hills, seemingly living his best life. He was at dinner with Paul McCartney and Eagles alum Joe Walsh at La Dolce Vita, an Old World Italian restaurant with long white...

Top Apple Executive Defends Favoring Google on iPhones

Apple’s top deal maker on Tuesday defended his company’s favoritism of Google on iPhones, a pivotal collaboration that has shaped the modern tech industry and is at the center of a federal antitrust trial against the search giant.Eddy Cue, Apple’s senior vice president of services, testified...

‘Unprecedented’ Secrecy in Google Trial as Tech Giants Push to Limit Disclosures

In a court filing last month, Google argued that it needed its privacy in an antitrust trial that would spotlight its dominance in online search.“Once commercially sensitive information is disclosed in open court, the resulting harm to the party’s competitive standing cannot be undone,” the internet...

How Jalen Hurts finally got the best of Todd Bowles

His stats weren’t particularly pretty. Two interceptions will do that. Still, there were some very encouraging signs from Jalen Hurts Monday night, and he didn’t hide his happiness – or maybe relief is a better word – for finally leaving Tampa with a win. It was at...

‘PAW Patrol 3’ In The Works From Paramount, Nickelodeon & Spin Master

Paramount Days before Spin Master/Paramount/Nickelodeon’s PAW Patrol: The Mighty Movie opens with a shot at No. 1 and $20M, a third theatrical movie has been announced for 2026. The long-running preschool franchise, which is celebrating its tenth anniversary, saw its first theatrical release under Paramount (and Elevation...

David McCallum, Heartthrob Spy of ‘The Man From U.N.C.L.E.,’ Dies at 90

David McCallum, the Scottish-born actor who became a surprise sensation as the enigmatic Russian spy Illya Kuryakin on “The Man From U.N.C.L.E.” in the 1960s and found television stardom again almost 40 years later on the hit series “N.C.I.S.,” died on Monday in Manhattan. He was...

CMF by Nothing launches earbuds, smartwatch, charger (Update: Availability)

TL;DR CMF by Nothing is a new sub-brand that uses the same in-house design team as mainline Nothing products. The first three devices from this sub-brand are earbuds, a smartwatch, and a GaN charger. The products are incredibly inexpensive and will come to the UK at first. India is...

Warriors newcomer Chris Paul can win the room with 11-word declaration

The wisest and classiest move Chris Paul can make in the coming days is to extinguish the fire that started with his cryptic response in his first meeting with reporters assigned to the Warriors. Sometime before next Monday, when Paul and his new teammates gather for media...

Biden, Trump to woo unions in Michigan as auto strikes grow

DETROIT, Sept 26 (Reuters) - Joe Biden and Donald Trump will speak to striking auto workers in rare back-to-back events in Michigan this week, highlighting the importance of union support in the 2024 presidential election, even though unions represent a tiny fraction of U.S. workers.Biden will...