Live data from Hacker News

Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

trustedsec.com

11–20 of 116 posts

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#11

Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ... https://arstechnica.com/information-technology/2026/03/feder...

In which one expert called the documentation provided "a pile of shit", which propublica took the liberty of extending to Azure itself

And they weren’t wrong

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#12

Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ... https://arstechnica.com/information-technology/2026/03/feder...

Every security engineer I know working at Azure is on the verge of self-harm because of the current situation, or is the dumbest IC I've ever met and somebody I think should have never become a security engineer. Sample size ~12.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#14

Yesterday ProPublica and ArsTechnica published a takedown of Azure: "Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway" ... https://arstechnica.com/information-technology/2026/03/feder...

Bloomberg and CNBC don't seem to have reported about this, maybe someone with contacts could make them aware?

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#15
Maybe I can use one of these to get in to my organization azure account from my alma mater. The email was deleted right after I graduated, but Microsoft has been trying to bill me (for a reserved IP or something) for close to a decade. Support is useless of course.

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#18
> It's not often that you see a demo of an actual Azure vulnerability, as they get patched and are gone forever. However, because Microsoft was having trouble replicating this complicated bypass, and asked for a video, I come bearing receipts.

Absolutely savage lol

[If you didn't read the thing, it's one curl command.]

Re: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found

#19

Puts me in mind of this scathing report from CISA on how a state-sponsored group broke into Microsoft and then into the State Department and a bunch of other agencies. Reads like a heist movie. https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi... What I found most incredible about the story is that it wasn't Microsoft who found the intrusion. It was some sysadmin at State who saw that some mail logs did no…

Ah yes, back when the US actually had cyber defence and experts capable of working in their respective fields.
Post reply on HN