Microsoft Warns of Hackers Targeting Azure Tags Customers
Microsoft seems to have had a slight change of heart when it comes to the security risk its Azure Service Tags are posing.
While initially claiming the tool was never meant to be a security measure, the company is now warning users that there are scenarios in which Service Tags could be used to gain unauthorized access to cloud resources.
Microsoft did stress that such scenarios were not yet observed in the wild and that there is no evidence of abuse in the real world (yet).
Not a security boundaryEarlier in 2024, cybersecurity researchers from Tenable claimed Azure Service Tags were vulnerable to a flaw that could let threat actors steal people’s sensitive data. Service Tags is a feature that helps simplify network security management by allowing users to define network access controls based on logical groups of IP addresses rather than individual IP addresses. These service tags represent a group of IP address prefixes from specific Azure services, which can be used in security rule..