Browsing tag

Azure

Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports

The recent attack against Microsoft’s email infrastructure by a Chinese nation-state actor referred to as Storm-0558 is said to have a broader scope than previously thought. According to cloud security company Wiz, the inactive Microsoft account (MSA) consumer signing key used to forge Azure Active Directory (Azure AD or AAD) tokens to gain illicit access […]

Researchers Disclose Details of Critical ‘CosMiss’ RCE Flaw Affecting Azure Cosmos DB

Microsoft on Tuesday said it addressed an authentication bypass vulnerability in Jupyter Notebooks for Azure Cosmos DB that enabled full read and write access. The tech giant said the problem was introduced on August 12, 2022, and rectified worldwide on October 6, 2022, two days after responsible disclosure from Orca Security, which dubbed the flaw […]

Microsoft Confirms Server Misconfiguration Led to 65,000+ Companies’ Data Leak

Microsoft this week confirmed that it inadvertently exposed information related to thousands of customers following a security lapse that left an endpoint publicly accessible over the internet sans any authentication. “This misconfiguration resulted in the potential for unauthenticated access to some business transaction data corresponding to interactions between Microsoft and prospective customers, such as the […]

Microsoft Azure customer hit by 2.4 Tbps DDoS attack

Microsoft has confirmed to mitigate a massive DDoS attack originated from a botnet comprising 70,000 compromised IoT devices. Microsoft reported that an unnamed customer of its Azure cloud platform was targeted with a 2.4 Tbps DDoS attack in the last week of August, which the company mitigated. This DDoS attack was around 140% higher than […]

Mirai botnet exploiting Azure OMIGOD vulnerabilities

The infamous Mirai botnet lets threat actors use compromised devices to carry out large-scale and crippling DDoS attacks. Critical Microsoft Azure vulnerabilities reported and patched earlier this week are actively exploited by threat actors and cybercriminals. Dubbed the OMIGOD flaws; the vulnerabilities were originally discovered by the Wiz Research Team. READ: Microsoft warns of Azure […]

Microsoft warns of Azure vulnerability which exposed users to data theft

Currently, there is no evidence that this particular Azure vulnerability was exploited to gain unauthorized access to customer data. In its newest blog post, Microsoft’s Security Response Center (MSRC) has warned Azure cloud computing users about a flaw in the system that allows hackers to access their data. RECENT: Hackers accessed primary keys of Azure’s Cosmos […]

Whitehat hackers accessed primary keys of Azure’s Cosmos DB customers

According to researchers, “This is the worst cloud vulnerability you can imagine.” A critical security vulnerability present in Microsoft’s Azure cloud computing database left the sensitive data of thousands of customers exposed. These customers included several Fortune 500 companies. The vulnerability existed in Microsoft Azure’s flagship database service Cosmos DB for approximately two years. The […]

US supermarket giant Wegmans exposed sensitive data

It took Wegmans a month to respond and secure its data after the Website Planet Security Team’s alerted the company about the issue. In recent news, Wegmans Food Markets, Inc., a private US supermarket chain with 106 stores across the country, exposed sensitive credentials and through a misconfigured Microsoft Azure Blob Storage Server.  The total […]

Microsoft Warns of Cross-Account Takeover Bug in Azure Container Instances

Microsoft on Wednesday said it remediated a vulnerability in its Azure Container Instances (ACI) services that could have been weaponized by a malicious actor “to access other customers’ information” in what the researchers described as the “first cross-account container takeover in the public cloud.” An attacker exploiting the weakness could execute malicious commands on other […]

Sensitive source codes exposed in Microsoft Azure Blob account leak

The research team at vpnMentor, who discovered the data, believes that it belongs to Microsoft as some of the files appeared to originate from a series of pitches made to Microsoft Dynamics Recently vpnMentor’s research team led by Noam Rotem uncovered a data breach that may presumably be owned by one of the biggest companies […]

ScoutSuite – Multi-Cloud Security Auditing Tool

  Scout Suite is an open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments. Using the APIs exposed by cloud providers, Scout Suite gathers configuration data for manual inspection and highlights risk areas. Rather than going through dozens of pages on the web consoles, Scout Suite presents a clear view of […]

Microsoft Asks Researchers To “Do Their Worst,” Doubles Azure Bounty To $40,000

At the ongoing Black Hat USA 2019 conference, Microsoft announced the Azure Security Lab ‚ a sandbox-like environment for security researchers to test Azure security without putting the company’s customers at risk. The new Azure Cloud host testing environment will allow security researchers to test attacks on infrastructure-as-a-service (IaaS) scenarios without affecting users. With isolated […]

Hackers Abusing Microsoft Azure to Deploy Malware and C2 Servers Using Evasion Technique

Now Microsoft Azure becomes a sweet spot for hackers to host powerful malware and also as a command and control server for sending and receiving commands to compromised systems. Microsoft Azure is a cloud computing platform created by Microsoft for building, testing, deploying, and managing applications and services through Microsoft-managed data centers. Initially, this malicious […]

Microsoft Introduces The World’s First AI-Generated Whiskey

Artificial intelligence is helping the world by assisting in all sorts of problems from reading minds to appearing as a witness in law trials. Now, AI is creating perfect whiskey blends for us. Microsoft has partnered with a 20-year-old Swedish distillery named Mackmyra and Fourkind, a Finnish technology consultancy — to bring forth the world’s first AI-created […]

Microsoft Launches New ‘Cloud PC Peripheral’ Hiding A Kinect Sensor #MWC 2019

Microsoft might have scrapped the Kinect accessory for the Xbox gaming console, but the company hinted back then that the technology would live and power more of its products. So, at MWC 2019 Microsoft just unveiled a new hardware device, powered by its Azure cloud platform, that uses the Kinect technology to carry out motion sensing, speech recognition, […]

Check your Microsoft Azure database; some of them were mistakenly deleted

The technological giant is in the process of recovering the deleted information The shut in Azure service last January 29 caused unheard damage. According to network security and ethical hacking experts from the International Institute of Cyber Security, the incident caused the deletion of the databases of some of the users of this service.  The […]

Linux Is Powering Almost Half Of All Microsoft Azure Virtual Machines

Around 40% of Microsoft’s Azure VMs now run Linux distributions, according to a tweet made by Microsoft Developer UK twitter account, ZDNet reports. That information was retweeted by Linuxing community manager Brian Byrne. Did you know that 40% of #VirtualMachines in #Azure are running #Linux? #FutureDecoded #Dev pic.twitter.com/Ypb667Oa1L — Microsoft Developer (@msdevUK) October 31, 2017 Only […]

Microsoft Brings Intel’s Clear Linux Operating System To Azure

Short Bytes: Microsoft has announced that it has brought support for Intel’s Clear Linux to its Azure cloud platform. This makes Microsoft the first cloud vendor to offer Clear Linux to its users. The company calls this OS a perfect fit for data center and cloud environments. Currently, it’s being offered to Azure customers as a […]

33% Of Microsoft Azure Virtual Machines Now Run Linux Operating System

Short Bytes: Microsoft’s investments in cloud-based open source technologies is now paying off. Thanks to the high demand for Linux on Azure, more Linux-lovers are choosing Redmond’s cloud platform. As a result, today, about one-third of Azure virtual machines are running Linux. If you think that Microsoft’s love for Linux and open source is selfless, think […]

Microsoft Creates Its Own Distribution Of FreeBSD Operating System

Short Bytes: Microsoft has released its own FreeBSD distribution and offered official support to Azure users. The kernel level changes/investments made by Redmond will be up-streamed into the official FreeBSD 10.3 release. Justin T. Gibbs, the FreeBSD Foundation’s President, called its an important milestone for the community.  Wwriting the latest chapter of its love affair with open […]

Microsoft Wants To Teach You How To Use Linux With Its New Certification Program

Image: Microsoft Short Bytes: Few years ago, Linux and Microsoft were fierce enemies as Redmond railed against the open source software. However, the tech giant has softened its approach and showed its love for Linux at many occasions in recent past. Along the similar lines, Microsoft has just offered a certification program that’ll teach you how to […]