Microsoft fixes major security flaw after “irresponsible” jibe
Microsoft has finally fixed a high-severity flaw that had been plaguing Azure users for five months after being called out on supposed lax security practices.
According to a report on BleepingComputer, Microsoft has released a patch on August 2, which fixes a flaw in the Power Platform Custom Connectors feature. The flaw allowed threat actors to access cross-tenant applications and Azure users sensitive data.
Cybersecurity researchers from Tenable were the first to discover the flaw in late March 2023, and the company’s CEO had heavily criticized Microsoft’s supposed inaction.
“Grossly irresponsible”
Cybersecurity researchers from Tenable were the first ones to discover the flaw in late March this year and claim it was a big one, as it allowed them to obtain secrets belonging to a bank (an unnamed one, but a Tenable customer, apparently). The researchers notified Microsoft immediately, which acknowledged the flaw and soon came up with a partial fix. After being warned that the released patch doesn’t fully address the problem, Microsoft gave a new deadline – September.
That would put the window of opportunity for hackers at roughly five months, which did not sit well with Tenable’s CEO, and that’s putting it mildly.
Amit Yoran went on to publish a LinkedIn blog post slamming Microsoft for its “negligence” when it comes to protecting its Azure users, describing the company’s activities as “grossly irresponsible”.
“Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers’ networks and services? Of course not. They took more than 90 days to implement a partial fix – and only for new applications loaded in the service,” Yoran said.
In an offficial security advisory posted, Microsoft said the problem is now fully fixed: “This issue has been fully addressed for all customers and no customer remediation action is required,” Microsoft said on Friday. The company added that it notified all of its customers of the fix, through the Microsoft 365 Admin Center. Notifications started going out on August 4.
Via: BleepingComputer
Microsoft has finally fixed a high-severity flaw that had been plaguing Azure users for five months after being called out on supposed lax security practices. According to a report on BleepingComputer, Microsoft has released a patch on August 2, which fixes a flaw in the Power Platform Custom Connectors feature.…
Recent Posts
- Here comes new Siri again
- ICYMI: the week’s 7 biggest tech stories, from Sony’s State of Play to Nvidia’s game-changing chip
- The Best 3-in-1 Apple Charging Stations After Testing Top Models
- ‘It’s becoming more difficult finding stable VPNs’ – China increases crackdown on VPN usage
- Google will pay SpaceX $920 million a month to use xAI’s data centers
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023