Multiple vulnerabilities in Microsoft's Azure Health Bot service were discovered, allowing access to sensitive infrastructure and confidential medical data. Issues included sandbox escapes, unrestricted code execution, access to authentication secrets, cross-tenant data exposure, and unauthorized deletion of resources. Microsoft quickly patched the vulnerabilities and restructured the service architecture for improved security.
Monitor for unusual access patterns or data requests in Azure Health Bot service. Implement logging and auditing for authentication and data access events. Regularly review and update access controls and sandbox configurations.