Tuesday, May 17, 2022

Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances

This post is also available in: 日本語 (Japanese)

Executive Summary

Azure Container Instances (ACI) is Azure’s Container-as-a-Service (CaaS) offering, enabling customers to run containers on Azure without managing the underlying servers. Unit 42 researchers recently identified and disclosed critical security issues in ACI to Microsoft. A malicious Azure user could have exploited these issues to execute code on other users’ containers, steal customer secrets and images deployed to the platform, an…

Read More

Latest news
Related news