Security News

Azure's now-fixed Cosmos DB flaw could have been exploited to read, write any database
2021-08-27 01:16

Infosec outfit Wiz has revealed that Microsoft's flagship Azure database Cosmos DB could have been exploited to grant any Azure user full admin access - including the ability to read, write and delete data - to any Cosmos DB instance on Azure. Wiz has named the flaw ChaosDB. "By exploiting a chain of vulnerabilities in the Jupyter Notebook feature of Cosmos DB, a malicious actor can query information about the target Cosmos DB Jupyter Notebook," reads Wiz's explanation.

Critical Cosmos Database Flaw Affected Thousands of Microsoft Azure Customers
2021-08-27 00:59

Cloud infrastructure security company Wiz on Thursday revealed details of a now-fixed Azure Cosmos database vulnerability that could have been potentially exploited to grant any Azure user full admin access to other customers' database instances without any authorization. Cosmos DB is Microsoft's proprietary NoSQL database that's advertised as "a fully managed service" that "Takes database administration off your hands with automatic management, updates and patching."

Critical Cosmos Database Flaw Affected Thousands of Microsoft Azure Customers
2021-08-27 00:59

Cloud infrastructure security company Wiz on Thursday revealed details of a now-fixed Azure Cosmos database vulnerability that could have been potentially exploited to grant any Azure user full admin access to other customers' database instances without any authorization. Cosmos DB is Microsoft's proprietary NoSQL database that's advertised as "a fully managed service" that "Takes database administration off your hands with automatic management, updates and patching."

Microsoft now offers Windows 11 preview on Azure Virtual Desktop
2021-08-21 15:45

Starting this week, Microsoft customers can use the Azure Virtual Desktop to virtualize a Windows 11 preview desktop on Azure virtual machines. "Azure Virtual Desktop has become a popular cloud VDI platform to run desktops and apps in the cloud and deliver a full Windows experience to users virtually anywhere," said Kam VedBrat, GM for Windows Virtual Desktop at Microsoft.

Windows 365 exposes Microsoft Azure credentials in plaintext
2021-08-13 18:24

A security researcher has figured out a way to dump a user's unencrypted plaintext Microsoft Azure credentials from Microsoft's new Windows 365 Cloud PC service using Mimikatz. On August 2nd, Microsoft launched their Windows 365 cloud-based desktop service, allowing users to rent Cloud PCs and access them via remote desktop clients or a browser.

Microsoft adds Fusion ransomware attack detection to Azure Sentinel
2021-08-09 21:22

Microsoft says that the Azure Sentinel cloud-native SIEM platform is now able to detect potential ransomware activity using the Fusion machine learning model. Microsoft announced today that its cloud-based SIEM now supports Fusion detections for possible ransomware attacks and triggers high severity Multiple alerts possibly related to Ransomware activity detected incidents.

IronNet Cybersecurity expands support for detecting cyber attacks in Microsoft Azure
2021-08-06 01:30

IronNet Cybersecurity announced expanded support for detecting and preventing cyber attacks in Microsoft Azure. As a Microsoft partner, IronNet and its Collective Defense platform provide support that enables its Microsoft customers to execute safe and seamless migrations to the cloud amidst the aggressive volume and increasing sophistication of cyber threats.

Paian IT Solutions and Corent Technology offer its cloud optimization service on Azure Marketplace
2021-08-01 23:30

Paian IT Solutions and Corent Technology create a transactable presence for cloud optimization services on Microsoft's Azure Marketplace. Paian's vision is to reach the entire Azure customer base across the region, offering PASOS - Paian's Azure Spend and Optimization services.

Bot protection now generally available in Azure Web Application Firewall
2021-08-01 14:00

Microsoft has announced that the Web Application Firewall bot protection feature has reached general availability on Azure Application Gateway starting this week. Azure Web Application Firewall is a cloud-native service designed to protect customers' web applications from bot attacks, common exploits, as well as common web vulnerabilities, including cross-site scripting, SQL injection, broken auth, security misconfigurations, and more.

EMQ X Cloud now available on Microsoft Azure to help users carry out their IoT projects with MQTT
2021-07-28 01:00

EMQ announced that EMQ X Cloud is now available on Microsoft Azure. EMQ X Cloud is a fully managed MQTT service built on the worldwide used open-source MQTT broker - EMQ X, which has more than 10 million downloads and hundreds of thousands of deployments around the globe.