Friday, August 28, 2026
Follow on LinkedIn

Azure

Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack

A critical architectural flaw in Microsoft Azure's Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry,...

New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

A sophisticated new phishing attack technique called "ConsentFix" that combines OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts without requiring passwords or multi-factor authentication. The attack leverages the Azure CLI app to gain unauthorized access to victim accounts. The...

Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels. The flaw, categorized as an authentication bypass vulnerability, poses an immediate risk to organizations that rely on Azure Bastion for...

AzureHound Penetration Testing Tool Weaponized by Threat Actors to Enumerate Azure and Entra ID

AzureHound, an open-source data collection tool designed for legitimate penetration testing and security research, has become a favored weapon in the hands of sophisticated threat actors. The tool, which is part of the BloodHound suite, was originally created to help...

Critical Azure & Power Apps Vulnerabilities Let Attackers Escalate Privileges

Microsoft has patched four critical security vulnerabilities affecting several core cloud services including Azure DevOps, Azure Automation, Azure Storage, and Microsoft Power Apps.  These high-severity flaws, disclosed on May 9, 2025, could potentially allow attackers to escalate privileges and compromise...

Detecting Vulnerable Commvault Environments Within Azure Using KQL Query

Cybersecurity analysts are racing to respond to an active exploitation campaign targeting Commvault environments in Microsoft Azure through the recently identified CVE-2025-3928 vulnerability. This critical vulnerability, which enables authenticated attackers to compromise web servers through the creation and execution...

Hackers Leveraging Azure App Proxy Pre-authentication to Access Orgs Private Network Resources

Recent security findings reveal that threat actors are actively exploiting misconfigured Azure application proxies to gain unauthorized access to organizations' internal resources.  When Azure app proxy pre-authentication is set to "Passthrough" instead of the default "Microsoft Entra ID" setting, private...

DeepSeek is Now Available With Microsoft Azure AI Foundry & GitHub

Microsoft has officially announced the integration of DeepSeek R1, an AI model, into its Azure AI Foundry platform and GitHub.  This move positions DeepSeek R1 among over 1,800 models, including frontier, open-source, and task-specific AI solutions.  The integration aims to provide...

Latest News

Latest News