Default Azure Automation Setting Enabled Cross-Tenant Identity Takeovers

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-24
Category: technology
Source: Dark Reading

Microsoft has addressed a critical vulnerability (CVE-2025-29827) in its Azure Automation service, which could have allowed attackers to seize another tenant's identity and access sensitive data, credentials, and cloud workloads. The flaw stemmed from a default configuration that made Azure Automation accounts publicly accessible, combined with two code-level bugs. While Microsoft has changed the default setting, organizations are advised to audit the scope of identities and tokens assigned to cloud automation accounts.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai