Acquiring administrative access to Azure's RedHat Update infrastructure
ianduffy.ie
ianduffy.ie
And given how hard it is to detect backdoor software, this is a HUGE security blunder. This could have literally installed a rootkit on every rhel instance on Azure.
Now the author states the keys have been rotated but now the next hacker know where to look.
Considering that's from Redhat, and not Microsoft, I do wonder if this is a non sensible default setup issue and there may be many enterprises running this out in the open.
"Additionally, if you duplicated a Red Hat Enterprise Linux virtual hard disk and created a new instance from it all billing association seemed to be lost but repository access was still available"
I'm confident that duplicating the virtual disk, certificates or installing the documented RPMs will result in repository access without being billed accordingly. It is considered fraud and I would imagine if one took large advantage of one would be disciplined accordingly.