A software repository on GitHub dedicated to supplying open-source code and AI models for image recognition was left open to manipulation by bad actors due to an insecure URL. This URL enabled visitors to the software repository to download AI models from an Azure storage container, which contained 38TB of data, including passwords, secret keys, and Microsoft Teams messages. Microsoft promptly plugged the leak and reported that no customer data was exposed.
