Palo Alto Networks Unit 42 reported a cross-account container takeover issue affecting Azure Container Instances (ACI), in which weaknesses in the service could allow one tenant to interfere with or gain control over containers belonging to another account. The finding raised concerns about tenant isolation in Microsoft’s serverless container platform, where customers rely on the cloud provider to enforce strict separation between workloads running on shared infrastructure.
The reported issue highlighted the risk that a compromise in ACI’s isolation model could expose customer applications, data, and credentials hosted inside affected containers. For defenders, the incident underscored the need to review cloud workload exposure in ACI, monitor for unauthorized container activity, and assess whether sensitive workloads should be segmented or moved until provider-side mitigations are confirmed.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research describing a cross-account container takeover issue affecting Azure Container Instances. The reference indicates public disclosure of the vulnerability but provides no additional event details such as patch timing or exploitation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.