Security researcher Justin O'Leary disclosed a confused deputy vulnerability in Microsoft Azure Kubernetes Service (AKS) backup tool that could allow privilege escalation to cluster admin. The flaw enables attackers to bypass access controls through insufficient request source verification. Microsoft reportedly patched the issue silently without public disclosure or acknowledgment.
// Get alerts for Microsoft Azure