At a glance: Azure Automation enables cross-tenant identity takeovers through default configuration; Microsoft also has three critical infrastructure security vulnerabilities.
At BlackHat 2026, security researcher Jeffrey Schwartz presented a critical vulnerability in Azure Automation: The default setting enables cross-tenant identity takeover. Additionally, three critical security vulnerabilities in Microsoft’s infrastructure were disclosed, including one affecting Bing Images.
The vulnerability in Azure Automation presented at BlackHat 2026 affects the service’s default configuration. It allows attackers to take over identities across tenant boundaries and thereby gain access to resources in other Azure tenants.
In parallel, three additional critical security vulnerabilities in Microsoft’s infrastructure have been identified. One of these vulnerabilities affects the Bing Images service. The exact technical details and affected components were presented by Schwartz at the conference.
For CISOs, this combination of vulnerabilities is significant as it demonstrates both configuration-related risks in cloud services and fundamental infrastructure deficiencies. Azure environments should be reviewed for non-standard security settings in Automation accounts. The critical vulnerabilities in Bing Images point to necessary patches for Microsoft systems that should be deployed promptly.
Source: borncity.com · Published July 27, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.