Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Microsoft employees accidentally disclose sensitive internal login credentials on GitHub

Shulou Source: shulou.com Published: 2023-11-24 12:08:56 09月30日 Update

CTOnews.com, August 18, Microsoft employees have exposed sensitive login credentials for the company's online infrastructure. According to Vice, the vulnerability was first reported by spiderSilk, a network security research company, and later confirmed by Microsoft. The exposed data came from employees on GitHub, the article said.

Mossab Hussein, chief security officer of SpiderSilk, a cyber security company that discovered the problem, said that the number of accidents caused by source code and credential leaks is becoming more and more difficult to identify in advance. "We continue to observe that unexpected source code and credential leaks are part of the company's attack surface, and it is becoming more and more difficult to identify them timely and accurately," he said. this is a very challenging problem for most companies today. "

CTOnews.com learned that Azure is a Microsoft cloud computer service similar to Amazon AWS service. The leaked credentials are related to Microsoft's official tenant ID. Tenant ID is a unique identifier linked to a specific set of Azure users.

When asked several times, Microsoft declined to specify which systems the credentials were protecting, according to Vice. The leak did not access any sensitive data, and the company has taken more secure measures to prevent credential sharing.

Tags: Company Microsoft security credentials credentials more and more employees data source code network network security problems services accidents login difficulties incidents infrastructure infrastructure Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno OPPO Reno NVidia Shulou Technology Xiaomi MariaDB