


Microsoft AI researchers accidentally leaked 38TB of internal data, including private keys and passwords
IT Home News on September 18th, cloud security startup Wiz Research announced today that a data leak was discovered in Microsoft AI’s GitHub repository, all caused by a misconfigured SAS (IT Home NOTE: Caused by Shared Access Signature) token.
In terms of details, Microsoft's AI research team released open source training data on GitHub, but accidentally exposed 38TB of other internal data, including disk backups of the personal PCs of several Microsoft employees. The disk backup also contained secrets, private keys, passwords and more than 30,000 internal Microsoft Teams messages from hundreds of Microsoft employees.
This GitHub repository provides open source code and AI models for image recognition, and visitors are asked to download the model from an Azure storage URL. However, Wiz discovered that the URL was configured to
. The URL in question, which allegedly exposed the data since 2020, was also misconfigured to allow "full control" instead of "read-only" permissions, meaning anyone who knew where to look could Possible removal, replacement and injection of malicious content into it.
Wiz has reported this issue to Microsoft, with the reporting date being June 22nd. Microsoft announced the revocation of the SAS token two days later, on June 24. Microsoft said it completed its investigation into potential organizational impact on August 16th
The specific timeline of the entire incident is as follows:
July 20, 2020 - Initial submission of SAS tokens to GitHub; expiry date set for October 5, 2021- October 6, 2021 - SAS token expiration date updated to October 6, 2051
- June 22, 2023 - Wiz Research discovered the issue and reported it to Microsoft
- June 24, 2023 - Microsoft Announces SAS Token Expiration
- July 7, 2023 - SAS tokens replaced on GitHub
- August 16, 2023 - Microsoft completes internal investigation into potential impact
- September 18, 2023 - Wiz Research publicly discloses this
- refer to
The above is the detailed content of Microsoft AI researchers accidentally leaked 38TB of internal data, including private keys and passwords. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

The article reviews top AI art generators, discussing their features, suitability for creative projects, and value. It highlights Midjourney as the best value for professionals and recommends DALL-E 2 for high-quality, customizable art.

Meta's Llama 3.2: A Leap Forward in Multimodal and Mobile AI Meta recently unveiled Llama 3.2, a significant advancement in AI featuring powerful vision capabilities and lightweight text models optimized for mobile devices. Building on the success o

ChatGPT 4 is currently available and widely used, demonstrating significant improvements in understanding context and generating coherent responses compared to its predecessors like ChatGPT 3.5. Future developments may include more personalized interactions and real-time data processing capabilities, further enhancing its potential for various applications.

The article compares top AI chatbots like ChatGPT, Gemini, and Claude, focusing on their unique features, customization options, and performance in natural language processing and reliability.

The article discusses top AI writing assistants like Grammarly, Jasper, Copy.ai, Writesonic, and Rytr, focusing on their unique features for content creation. It argues that Jasper excels in SEO optimization, while AI tools help maintain tone consist

The article reviews top AI voice generators like Google Cloud, Amazon Polly, Microsoft Azure, IBM Watson, and Descript, focusing on their features, voice quality, and suitability for different needs.

Falcon 3: A Revolutionary Open-Source Large Language Model Falcon 3, the latest iteration in the acclaimed Falcon series of LLMs, represents a significant advancement in AI technology. Developed by the Technology Innovation Institute (TII), this open

2024 witnessed a shift from simply using LLMs for content generation to understanding their inner workings. This exploration led to the discovery of AI Agents – autonomous systems handling tasks and decisions with minimal human intervention. Buildin
