Stealth Fix or False Alarm? The Brewing Controversy Over Microsoft's Azure Security Stance
A security researcher and Microsoft are at odds over a reported critical vulnerability within Azure Backup for AKS (Azure Kubernetes Service). The researcher alleges that after reporting a flaw that could lead to unauthorized data access, Microsoft dismissed the findings as 'expected behavior' yet proceeded to quietly implement changes that mitigated the issue. Microsoft maintains that no product changes were made and has declined to issue a Common Vulnerabilities and Exposures (CVE) identifier. This dispute underscores the friction in the cybersecurity community regarding transparent bug reporting and the criteria for official vulnerability documentation.