Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Tenable CEO says Microsoft failed to address a serious security flaw

  • August 3, 2023
Total
0
Shares
0
0
0


The CEO of cybersecurity company Tenable has taken to LinkedIn to heavily criticize Microsoft on its practices when it comes to patching high-severity flaws and other dangerous vulnerabilities.

In a post published on (somewhat ironically) the Microsoft-owned platform, Amit Yoran said Microsoft has a history of non-transparent behavior with regards to breaches and vulnerabilities, “all of which expose their customers to risks they are deliberately kept in the dark about”.

The CEO says that his company discovered a high severity flaw in the Azure platform in March 2023, which could allow threat actors to quickly discover authentication secrets. To emphasize the importance of the findings, Yoran said that the analysts discovered secrets to a bank, and soon after, they notified Microsoft of the issues.

Many firms at risk

The Redmond software giant acknowledged the findings within days, but took some three months to release a patch which, according to Yoran, was partial and did not address the issue fully. It only worked for new applications loaded in the service. 

“That means that as of today, the bank I referenced above is still vulnerable, more than 120 days since we reported the issue, as are all of the other organizations that had launched the service prior to the fix,” he says. “And, to the best of our knowledge, they still have no idea they are at risk and therefore can’t make an informed decision about compensating controls and other risk mitigating actions.” 

According to Yoran, Microsoft promised a fix by the end of September, which is “grossly irresponsible, if not blatantly negligent,” he added.

His writeup sparked quite the debate on LinkedIn, with almost a hundred different comments and remarks. Many of the people who chimed in agree with Yoran’s remarks, with one cynically saying “so you’re basically saying that nothing has changed in 30 years?”.

Microsoft is yet to comment on these allegations.

Microsoft claims that they will fix the issue by the end of September, four months after we notified them. That’s grossly irresponsible, if not blatantly negligent. We know about the issue, Microsoft knows about the issue, and hopefully threat actors don’t. 

Cloud providers have long espoused the shared responsibility model. That model is irretrievably broken if your cloud vendor doesn’t notify you of issues as they arise and apply fixes openly. 

What you hear from Microsoft is “just trust us,” but what you get back is very little transparency and a culture of toxic obfuscation. How can a CISO, board of directors or executive team believe that Microsoft will do the right thing given the fact patterns and current behaviors? Microsoft’s track record puts us all at risk. And it’s even worse than we thought.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Microsoft is bringing Starfield and Forza to Gamescom but won’t be available to play

  • August 3, 2023
View Post
Next Article
  • News

Sonos Move 2 leak looks like a bigger Era 100, but with a 24-hour onboard battery

  • August 3, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Sunday, October 1 (game #615)

  • September 30, 2023
View Post
  • News

Mortal Kombat 1 creator teases that a host of terrifyingly familiar faces may be on the way

  • September 30, 2023
View Post
  • News

Google Pixel Buds Pro leak gives us an early look at some new colors

  • September 30, 2023
View Post
  • News

The Pokémon Company apologizes and blames “overwhelming demand” for its Van Gogh collab stock issues

  • September 30, 2023
View Post
  • News

Your next laptop could run faster, last longer and pack more memory thanks to Samsung’s revolutionary new technology — but it won’t be cheap

  • September 30, 2023
View Post
  • News

Early iPhone 16 leak hints at larger screens for the Pro and Pro Max models

  • September 30, 2023
View Post
  • News

Bad news – turns out even long passwords can be cracked easily

  • September 30, 2023
View Post
  • News

AMD has a new trick to make games run smoother – but only for RX 7000 GPUs

  • September 30, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.