Advertisement
Cloud Security Index 2026: Multi-Cloud Risk Analysis
Intruder analyzed cloud misconfigurations across AWS, Azure, and GCP, revealing distinct risk profiles and universal IAM challenges.
Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated
Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.
Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws
Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.
Threat Actor Claims 3.6 Million Azure Account Records Stolen
A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.
Microsoft & Apple Patch Critical RCEs and Auth Bypass Flaws
Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.
Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access
Wiz researchers uncover CosmosEscape, a sandbox escape in Azure Cosmos DB's Gremlin API allowing unauthorized cross-tenant read and write access.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Azure Automation Default Setting: Cross-Tenant Identity Takeover
Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts
A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.
Azure Backup for AKS Vulnerability: Risks of Silent Patches
A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.
Microsoft's 137 Patches: Critical Flaws in Azure, Windows, Dynamics
Microsoft's latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.
ConsentFix v3: How Attackers Automate Azure OAuth Abuse
Attackers use ConsentFix v3 to automate illicit consent grants in Microsoft Azure, enabling persistent access to Entra ID data without user passwords.
CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass
CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.
Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest
Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns
Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.