Yanir Tsarimi Profile picture
Hacker. I try to write about security in ways most can understand. Microsoft Most Valuable Researcher & Google Top Bug Hunter ‘22
Mar 7, 2022 10 tweets 3 min read
I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions

We all know vulnerabilities exist. This isn't an injection, XSS, or RCE.

But the crazy thing about it?
It took 2 hours to discover. 🤯

Here's the story of #AutoWarp👇 (1/10) Scrolling through the endless list of Azure services, I’m looking for a new target

So I click “Automation Accounts” not really knowing what it even means. I quickly realized that this is basically a service for running Python & PowerShell scripts. 🧐 (2/10)