{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/azure-ai-foundry/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Azure AI Foundry","Azure API Management"],"_cs_severities":["high"],"_cs_tags":["azure-ai-foundry","credential-access","genai","data-leakage","cloud-security"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eOrganizations utilizing Azure AI Foundry through API Management are at risk of sensitive information disclosure when users or automated processes inadvertently include secrets, such as API keys, private keys, or credentials, within LLM prompts. Because Azure content filters often do not flag these prompts as policy violations, the secrets are processed and potentially echoed back in assistant completions. This exposure occurs at the application layer and is recorded within API Management GatewayLogs. Defenders must ingest these logs with backend request and response bodies to achieve visibility. Detecting these patterns is essential to preventing LLM data leakage, identifying compromised credentials for rotation, and tracing the source of the exposure to specific API Management subscriptions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation or accidental disclosure results in the exposure of live authentication secrets, potentially leading to unauthorized access to downstream cloud services, developer environments, or internal APIs. Organizations may suffer from secondary credential abuse, such as unauthorized cloud infrastructure access using leaked AWS keys, private keys, or OAuth tokens transmitted through AI interfaces.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Azure API Management GatewayLogs with backend request and response body logging to capture full interaction text.\u003c/li\u003e\n\u003cli\u003eImplement the provided detection logic to monitor API Management logs for patterns matching known credential structures (e.g., AWS access keys, GitHub tokens, Slack tokens, private keys).\u003c/li\u003e\n\u003cli\u003eTreat all detections as potential incidents; rotate or revoke any identified live credentials immediately.\u003c/li\u003e\n\u003cli\u003eRestrict access to raw API request/response logs to authorized security teams, as these logs retain the cleartext secrets that triggered the alert.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T17:57:07Z","date_published":"2026-10-05T17:57:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-azure-ai-credential-leakage/","summary":"This detection monitors Azure API Management GatewayLogs for sensitive credential patterns accidentally included in LLM prompts or assistant replies, flagging potential data leakage through AI services.","title":"Detection of Credential Exposure in Azure AI Foundry Interactions","url":"https://feed.craftedsignal.io/briefs/2026-10-azure-ai-credential-leakage/"}],"language":"en","title":"CraftedSignal Threat Feed - Azure-Ai-Foundry","version":"https://jsonfeed.org/version/1.1"}