A critical architectural flaw in Microsoft Azure's Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources.
The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry,...
A sophisticated new phishing attack technique called "ConsentFix" that combines OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts without requiring passwords or multi-factor authentication.
The attack leverages the Azure CLI app to gain unauthorized access to victim accounts.
The...
A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels.
The flaw, categorized as an authentication bypass vulnerability, poses an immediate risk to organizations that rely on Azure Bastion for...
AzureHound, an open-source data collection tool designed for legitimate penetration testing and security research, has become a favored weapon in the hands of sophisticated threat actors.
The tool, which is part of the BloodHound suite, was originally created to help...
Microsoft has patched four critical security vulnerabilities affecting several core cloud services including Azure DevOps, Azure Automation, Azure Storage, and Microsoft Power Apps.
These high-severity flaws, disclosed on May 9, 2025, could potentially allow attackers to escalate privileges and compromise...
Cybersecurity analysts are racing to respond to an active exploitation campaign targeting Commvault environments in Microsoft Azure through the recently identified CVE-2025-3928 vulnerability.
This critical vulnerability, which enables authenticated attackers to compromise web servers through the creation and execution...
Recent security findings reveal that threat actors are actively exploiting misconfigured Azure application proxies to gain unauthorized access to organizations' internal resources.
When Azure app proxy pre-authentication is set to "Passthrough" instead of the default "Microsoft Entra ID" setting, private...
Microsoft has officially announced the integration of DeepSeek R1, an AI model, into its Azure AI Foundry platform and GitHub.
This move positions DeepSeek R1 among over 1,800 models, including frontier, open-source, and task-specific AI solutions.
The integration aims to provide...