Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
AI disclosure
Summary
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads.