Security News

CISA says SaaS providers in firing line after Commvault zero-day Azure attack
2025-05-23 16:45

Cyberbaddies are coming for your M365 creds, US infosec agency warns The Cybersecurity and Infrastructure Security Agency (CISA) is warning that SaaS companies are under fire from criminals on the...

Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server
2025-05-14 08:14

Microsoft on Tuesday shipped fixes to address a total of 78 security flaws across its software lineup, including a set of five zero-days that have come under active exploitation in the wild. Of...

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach
2025-05-01 08:11

Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no...

Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach
2025-04-22 07:38

Microsoft on Monday announced that it has moved the Microsoft Account (MSA) signing service to Azure confidential virtual machines (VMs) and that it's also in the process of migrating the Entra ID...

Microsoft Exposes LLMjacking Cybercriminals Behind Azure AI Abuse Scheme
2025-02-28 10:33

Microsoft on Thursday unmasked four of the individuals that it said were behind an Azure Abuse Enterprise scheme that involves leveraging unauthorized access to generative artificial intelligence...

Microsoft names alleged credential-snatching 'Azure Abuse Enterprise' operators
2025-02-28 04:02

Crew helped lowlifes generate X-rated celeb deepfakes using Redmond's OpenAI-powered cloud – claim Microsoft has named four of the ten people it is suing for allegedly snatching Azure cloud...

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score
2025-02-04 05:08

Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges...

Azure, Microsoft 365 MFA outage locks out users across regions
2025-01-13 17:55

It's fixed, mostly, after Europeans had a manic Monday Microsoft's multi-factor authentication (MFA) for Azure and Microsoft 365 (M365) was offline for four hours during Monday's busy start for...

Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content Creation
2025-01-11 07:54

Microsoft has revealed that it's pursuing legal action against a "foreign-based threat–actor group" for operating a hacking-as-a-service infrastructure to intentionally get around the safety...

Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation
2024-12-31 04:35

Cybersecurity researchers have uncovered three security weaknesses in Microsoft's Azure Data Factory Apache Airflow integration that, if successfully exploited, could have allowed an attacker to...