Security News

Researchers Find Vulnerabilities in Microsoft Azure Cloud Service
2020-10-08 06:56

Now according to the latest research, two security flaws in Microsoft's Azure App Services could have enabled a bad actor to carry out server-side request forgery attacks or execute arbitrary code and take over the administration server. Azure App Service is a cloud computing-based platform that's used as a hosting web service for building web apps and mobile backends.

Microsoft Paid Out Over $374,000 for Azure Sphere Vulnerabilities
2020-10-07 03:35

Microsoft on Tuesday shared the results of its three-month-long Azure Sphere Security Research Challenge and the company says it has paid out more than $374,000 to participants. The Azure Sphere Security Research Challenge, announced in May, invited security researchers to find vulnerabilities in Azure Sphere, Microsoft's IoT security solution, which the tech giant designed to provide end-to-end security across hardware, operating system and the cloud.

Microsoft pays over $370,000 for Azure Sphere bug reports
2020-10-06 12:00

Microsoft awarded over $370,000 in bounties to security researchers for 16 bounty eligible reports of vulnerabilities submitted through the Azure Sphere Security Research Challenge IoT-focused research program. Azure Sphere Security Research Challenge is a 3-month expansion to the Azure Security Lab bounty program Microsoft announced last year at Black Hat 2019.

Azure Kubernetes Service Now Supports Confidential Containers
2020-10-02 10:51

Microsoft this week announced the public preview of support for confidential computing nodes in Azure Kubernetes Service. One of the big tech companies to have affirmed commitment to computing confidentiality, Microsoft made Azure Confidential Computing generally available earlier this year, and also expanded the availability of secure VMs. The availability of confidential containers on AKS is yet another step Microsoft is taking toward moving computing from 'in the clear' to 'confidential'.

Microsoft Azure customers can now implement Datadog as a monitoring solution for their cloud workloads
2020-10-01 23:30

This means that Azure customers will be able to implement Datadog as a monitoring solution for their cloud workloads through new streamlined workflows that cover everything from procurement to configuration. The improved onboarding experience makes Datadog setup automatic, so new users can start monitoring the health and performance of their applications with Datadog quickly, whether they are based entirely in Azure or spread across hybrid or multi-cloud environments.

Unisys unveils ClearPath MCP Software Series for Microsoft Azure
2020-10-01 01:00

Unisys announced ClearPath MCP Software Series for Microsoft Azure the first availability of its flagship software environment in the public cloud. "ClearPath MCP Software Series for Azure affords organizations a more seamless transition to hybrid and multi-cloud environments, with reduced risk and time to achieve value from the cloud," said Vishal Gupta, senior vice president, Products and Platforms and Chief Technology Officer, Unisys.

odix joins MISA program and integrates its FileWall with Microsoft Azure Sentinel
2020-09-30 23:30

Odix was nominated to MISA for integrating their recently launched product, FileWall, with Microsoft Azure Sentinel. FileWall is a security application for Microsoft 365 mailboxes and now includes reporting capabilities to Azure Sentinel.

Microsoft Says China-Linked Hackers Abused Azure in Attacks
2020-09-27 11:40

Microsoft Reports Evolution of China-Linked Threat Actor GADOLINIUM. Microsoft this week announced that it recently removed 18 Azure Active Directory applications that were being abused by China-linked state-sponsored threat actor GADOLINIUM. Also known as APT40, TEMP.Periscope, TEMP.Jumper, Leviathan, BRONZE MOHAWK, and Kryptonite Panda, the adversary has been active since at least 2013, mainly operating in support of China's naval modernization efforts, through targeting various engineering and maritime entities, including a U.K.-based company. The threat actor was recently observed leveraging Azure cloud services and open source tools in attacks employing spear-phishing emails with malicious attachments.

Microsoft Kills 18 Azure Accounts Tied to Nation-State Attacks
2020-09-25 15:26

An APT group has started heavily relying on cloud services like Azure Active Directory and OneDrive, as well as open-source tools, to obfuscate its attacks. Microsoft has suspended 18 Azure Active Directory applications that were being leveraged for command-and-control infrastructure by what it says is a Chinese nation-state actor.

Jumio’s AI-powered identity verification solutions now available for Microsoft Azure Active Directory B2C
2020-09-24 00:00

Jumio announced that its AI-powered identity verification solutions are now available to Microsoft Azure Active Directory External Identities for B2C customers. Azure Active Directory B2C is a customer identity access management solution.