Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access
Wiz researchers uncover CosmosEscape, a sandbox escape in Azure Cosmos DB's Gremlin API allowing unauthorized cross-tenant read and write access.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Azure Automation Default Setting: Cross-Tenant Identity Takeover
Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts
A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.
Falcon Cloud Security Expands Multi-Cloud Coverage for Azure, GCP
CrowdStrike Falcon Cloud Security's latest updates enhance multi-cloud protection across Azure and Google Cloud, improving visibility and threat detection.
Azure Backup for AKS Vulnerability: Risks of Silent Patches
A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.
Microsoft's 137 Patches: Critical Flaws in Azure, Windows, Dynamics
Microsoft's latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.
ConsentFix v3: How Attackers Automate Azure OAuth Abuse
Attackers use ConsentFix v3 to automate illicit consent grants in Microsoft Azure, enabling persistent access to Entra ID data without user passwords.
CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass
CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.
Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest
Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns
Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.