Security News

Microsoft outage caused by overloaded Azure DNS servers
2021-04-03 12:15

Microsoft has revealed that Thursday's worldwide outage was caused by a code defect that allowed the Azure DNS service to become overwhelmed and not respond to DNS queries. Last night, Microsoft published a root cause analysis for this week's outage and explained that it was caused by their Azure DNS service becoming overloaded.

AVSystem integrates Coiote IoT DM with Microsoft Azure IoT Hub and AWS IoT Core through LwM2M
2021-03-24 02:30

AVSystem announced integration of the Coiote IoT Device Management service with both Microsoft Azure IoT Hub and Amazon Web Services IoT Core via Lightweight M2M. Coiote is the first IoT device management platform in the industry to provide support for constrained IoT devices at scale for both cloud providers. This opens new opportunities for creating IoT services over low-power wide area network within Azure and AWS. By combining device energy savings and lower data consumption with existing cloud services, enterprises can reduce time to market and decrease costs for deploying IoT solutions and managing IoT operations.

Datadobi adds support for Azure Blob storage in DobiProtect 5.11
2021-03-18 01:45

Datadobi announced it has added support for Azure Blob storage in DobiProtect 5.11, enabling customers to protect their data from any NAS or cloud filesystem to Microsoft's cloud-based object storage solution. Azure Blob storage is a massively scalable and secure object storage service for data lakes, archives, cloud-native workloads, analytics, and machine learning.

Microsoft's Azure SDK site tricked into listing fake package
2021-03-17 08:01

A security researcher was able to add a counterfeit test package to the official list of Microsoft Azure SDK latest releases. The simple trick if abused by an attacker can give off the impression that their malicious package is part of the Azure SDK suite.

Researcher adds his fake package to Microsoft Azure SDK releases list
2021-03-17 08:01

A security researcher was able to add a counterfeit test package to the official list of Microsoft Azure SDK latest releases. The simple trick if abused by an attacker can give off the impression that their malicious package is part of the Azure SDK suite.

Researcher adds their package to Microsoft Azure SDK releases list
2021-03-17 08:01

A security researcher was able to add a counterfeit test package to the official list of Microsoft Azure SDK latest releases. The simple trick if abused by an attacker can give off the impression that their malicious package is part of the Azure SDK suite.

Tiberium launches two Microsoft based services leveraging Azure Sentinel and Microsoft Defender
2021-03-17 02:45

Cybersecurity innovator Tiberium launched two Microsoft based services leveraging Azure Sentinel and Microsoft Defender. Founded by Kiwi, Drew Perry, the launch sees the first major step for Tiberium since closing a successful funding round and welcoming experienced security players to the Board at the turn of the year.

Microsoft shares detection, mitigation advice for Azure LoLBins
2021-03-09 18:05

Attackers can abuse a wide range of Window legitimate tools, including but not limited to Microsoft Defender, Windows Update, and even the Windows Finger command. While being legitimately used by thousands of admins each day for managing their organizations' Azure fleets, their capabilities can also be used for malicious purposes, including circumventing network defense lines.

Azure flings out free virtual trusted platform module for cloudy VMs
2021-03-09 05:58

Microsoft has revealed that its Azure IaaS platform now offers free a virtual trusted platform module. Dubbed "Azure Trusted Launch for virtual machines" and launched as a preview on March 8th, Microsoft's CTO for Azure Mark Russinovich said the new offering "Allows administrators to deploy virtual machines with verified and signed bootloaders, OS kernels, and a boot policy that leverages the Trusted Launch Virtual Trusted Platform Module to measure and attest to whether the boot was compromised."

Strata Maverics Identity Orchestrator extends Azure AD control to on-premise applications
2021-03-08 00:30

Strata announced at Microsoft Ignite that its Maverics Identity Orchestrator platform for Microsoft Azure Active Directory enables organizations to migrate applications to the Cloud without rewriting them so identity can be centrally managed by Azure AD. In addition, Strata allows companies to modernize on-premises apps by extending Azure AD authentication and access control capabilities to them with no code changes. Strata makes it possible to transition applications to Azure AD with no user experience changes and no burden on application teams, so organizations can manage and enforce consistent access across hybrid cloud environments.