Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Axis Communications Vulnerability Exposes Azure Storage Account Credentials

A critical vulnerability in the Autodesk Revit plugin by Axis Communications has exposed Azure Storage Account credentials, posing significant security risks for users and creating potential for supply chain attacks within the architecture and…

A critical vulnerability in the Autodesk Revit plugin by Axis Communications has exposed Azure Storage Account credentials, posing significant security risks for users and creating potential for supply chain attacks within the architecture and engineering sectors.

The vulnerability arises from hardcoded credentials within signed Dynamic Link Libraries (DLLs) distributed via the plugin’s Microsoft Installer (MSI) package.

The issue was identified in July 2024 when Trend Micro's VirusTotal rules detected Azure Shared Access Signature (SAS) tokens in a digitally signed DLL named "AzureBlobRestAPI.dll."

The affected component was provided to AEC Advanced Engineering Computation Aktiebolag, an Autodesk partner specializing in consulting for AutoCAD and Revit platforms.

The exposed credentials allowed unauthorized read and write access to three Azure storage accounts belonging to Axis Communications, a company specializing in network video solutions and surveillance technology.

The vulnerability is rooted in inadequate credential management within the plugin’s architecture.
Laura Mitchell · Thehackingpost

The vulnerability is rooted in inadequate credential management within the plugin’s architecture. Researchers discovered cleartext Azure SAS tokens and shared access key pairs for two Azure storage accounts, "axisfiles" and "axiscontentfiles," within a private method called "internalSetEnvironment" of the class "AzureBlobRestAPI.DataTypes.Classes.Global."

These credentials provided extensive privileges, including read, write, delete, list, add, create, update, process, and execute permissions across the storage accounts.

Axis Communications initially attempted remediation in version 25.3.710 through code obfuscation using tools like Eazfuscator. However, this was inadequate as the obfuscated credentials could be de-obfuscated using publicly available tools.

Advertisement

The vulnerability persisted due to historical plugin versions containing overly permissive credentials. Full remediation was achieved in version 25.3.718, with Axis Communications confirming all issues have been addressed.

Axis Communications has taken steps to notify affected partners and customers. The Autodesk Revit plugin is available only to select partners, not for public distribution.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories