SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • April 10, 2024
  • Rss Fetcher
Illustration of a password above an open combination lock, implying a data breach.
Cath Virginia / The Verge | Photo from Getty Images

Microsoft reportedly locked down a server last month that exposed passwords, keys, and credentials of Microsoft employees to the open internet, as the company faces mounting pressure to bolster its software security.

According to Techcrunch, three security researchers at SOCRadar — a company specializing in detecting corporate cybersecurity weaknesses — discovered that an Azure-hosted server storing sensitive data linked to Microsoft’s Bing search engine was left open with no password protection, meaning it could be accessed by anyone online. The server contained a variety of security credentials used by Microsoft employees to access internal systems, housed within various scripts, code, and configuration files.

The exposed credentials “could result in more significant data leaks and possibly compromise the services in use.”

One of the researchers, Can Yoleri, told Techcrunch that hackers could potentially use this exposed data to find and access other areas where Microsoft stores internal data, which “could result in more significant data leaks and possibly compromise the services in use.”

Microsoft was notified about the vulnerability on February 6th, and locked it down by March 5th. It’s unclear if anyone else accessed the exposed server during this time. We have reached out to Microsoft for comment and will update this story if we hear back.

Microsoft has faced several cybersecurity mishaps in recent years, and is currently in the process of overhauling its security practices. Earlier this month, a review from the US Cyber Safety Review Board said Microsoft could have prevented a breach in its Exchange Online software that allowed Chinese hackers to access US government email systems in 2023, accusing the tech giant of developing a “corporate culture that deprioritized enterprise security investments and rigorous risk management.” Another incident in 2022 saw sensitive login credentials for Microsoft’s systems being uploaded by its own employees on GitHub.

Previous Post
Next Post

Recent Posts

  • Probability of rolling a Yahtzee
  • AMD strikes a deal to sell ZT Systems’ server-manufacturing business for $3B
  • Google launches stand-alone NotebookLM app for Android
  • Chris’ Corner: Design Do’s and Don’ts
  • Trump to sign bill criminalizing revenge porn and explicit deepfakes

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.