Azure
131 incident problems in Azure environments.
먼저 읽을 가이드
추천 문제
All problems (131)
SECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-089SIEM suppression rule hides the second stage of an attackThe first alerts are known noise, but the actual compromise gets hidden because the suppression logic keys on a reused naming pattern across rebuilt hosts.SecurityAdvanced20 minProSECURITY-080Endpoint isolation policy blocks the EDR cloud callback and the host never recovers from containmentContainment starts correctly, but the host stays permanently isolated because the policy also cut off the control channel required to release it safely.SecurityAdvanced21 minProSECURITY-1211Federated login breaks only on callbackAn OIDC flow still reaches the provider successfully, but the callback handler rejects the return due to missing browser state.SecurityAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProSECURITY-062SIEM correlation deduplicates brute-force alerts and hides the real spray scopeAnalysts see only a few incidents, but the attack is much wider because the correlation rule collapses repeated signals into one coarse event group.SecurityAdvanced21 minProSECURITY-070EDR quarantine removes the log shipper binary and host visibility disappears without an alertThe endpoint agent did its job from one perspective, but security operations lose telemetry because the quarantined component was also the only path to central visibility.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProSECURITY-1203Central log pipeline is green but one parser update silently drops a whole class of security eventsCollection is alive and dashboards look healthy, yet one format change causes a parser to reject or discard a subset of events without obvious pipeline failure.SecurityAdvanced23 minProCICD-080Feature flag migration step runs before the dependent schema change reaches every shardThe rollout script succeeds centrally, but one shard still serves the old schema and the new flag path begins calling a column that does not exist everywhere yet.CI/CDAdvanced23 minProSECURITY-1181Internal registry trust breaksOperators rotate certificates after reading public advice, but only one served path is broken because it omits the intermediate chain.SecurityAdvanced24 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-1200mTLS breaks only on rotated clientsA certificate rollout follows community guidance and appears fine on servers. Client auth still fails on one path because not every validator tier received the new intermediate bundle.SecurityAdvanced24 minProLINUX-053rsyslog disk queue fills /var after the remote collector becomes unreachableCentral logging is configured correctly for healthy periods, but when the collector disappears the buffered queue grows until the local partition reaches pressure.LinuxAdvanced24 minProSECURITY-055EDR quarantine removes the log shipper binary and blinds central visibilityContainment works on the compromised host, but the action also stops telemetry collection and makes the rest of the investigation much harder.SecurityAdvanced25 minProSECURITY-015Emergency blocklist rule causes asymmetric egress failureEmergency blocklist rule causes asymmetric egress failure is a hands-on troubleshooting drill. A rapid security response closes the obvious path but unexpectedly breaks return traffic for a dependent service flow. Azure Incident Response Operations needs to be checked by narro...SecurityAdvanced28 minProSECURITY-024Incident response snapshot leaks secrets through copied temp filesA manual triage procedure preserves evidence, but the copied bundle accidentally includes secret-bearing temp artifacts.SecurityAdvanced28 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProSECURITY-030Threat containment playbook isolates attack but breaks blue team visibilityThe response action succeeds operationally, but telemetry from the isolated segment disappears and hinders further analysis.SecurityAdvanced29 minProSECURITY-1290A CSP rollout looks correct but one payment popup failsA security hardening rollout passes smoke tests and a third-party popup or embedded checkout later breaks in production.SecurityIntermediate15 minPro