THE article discusses a critical vulnerability in Microsoft's Azure Automation service that could allow attackers to seize identities of other tenants due to a default public configuration. Discovered by security researcher Shay Shavit, this vulnerability (CVE-2025-29827) has a CVSS score of 9.9 and could enable unauthorized access to sensitive data and resources across a cloud environment. Although Microsoft has updated the default setting, Shavit warns against exposing identities externally.
He emphasizes the importance of considering vulnerabilities within the context of potential exploit chains and highlights the growing significance of identities in cloud security. The piece also references past vulnerabilities and stresses the need for comprehensive security audits of cloud setups.