< ciso
brief />
Tag Banner

All news with #microsoft azure tag

87 articles

Responsible infrastructure and lifecycle of Azure hardware

๐Ÿ”ง Microsoft Azure outlines how it manages the full lifecycle of hyperscale hardware to balance increased compute density with responsible reuse and recycling. The company describes design, operation, secure decommissioning, and repurposing through its global Circular Centers, now expanded to North America, Europe, and Asia Pacific. Azure reports a 92% reuse and recycling rate and highlights automation and AI-driven disassembly to scale circular operations and support Zero Waste goals.
read more โ†’

SQL Server on Azure Local Now Generally Available

๐Ÿ”” Today Microsoft announced that SQL Server on Azure Local is generally available for both connected and disconnected operations, enabling organizations to run SQL Server on Azure-consistent infrastructure in customer datacenters and edge locations. The offering supports modernized deployments while preserving local control, data sovereignty, and licensing options. Customers can also preview Foundry Local to run AI inference alongside SQL Server on Azure Local.
read more โ†’

JadePuffer agentic AI attacks target Azure tenants

๐Ÿ”’ Researchers report that the JadePuffer ransomware operator is conducting agent-driven attacks against Azure tenants to perform reconnaissance, steal credentials, and destroy cloud resources. The campaign, first observed in July and tracked by Microsoft as Storm-3168, uses compromised service principals to map resources, retrieve storage keys, and delete storage accounts, Key Vaults, VMs, and more. Some deletions were blocked by Azure resource locks and other protections, and several failed deletion attempts occurred due to unsupported API calls. Experts advise enabling cloud workload protections, auditing for exposed secrets, and applying least-privilege RBAC policies.
read more โ†’

Autonomous agents destroy Azure resources using identities

๐Ÿ›ก๏ธ Microsoft warns that an autonomous attacker known as Jadepuffer (Storm-3168) has expanded into Azure, using compromised service principals to enumerate resources, delete cloud assets and harvest credentials. The campaign involved two service principals splitting reconnaissance and destructive duties, with rapid automated actions that deleted storage accounts, a Key Vault, Function App and other resources. After destruction the actors requested storage account keys, raising concerns about recovery and potential future exfiltration. Microsoft urges securing workload identities, enforcing least privilege and protecting backup and recovery controls.
read more โ†’

Microsoft updates cause desktop loading issues

๐Ÿ› ๏ธ Microsoft confirmed that some users experience desktop loading problems, including black screens, after installing August 2026 preview updates and later updates. The issue primarily affects Azure Virtual Desktop hosts using FSLogix, causing black screens after sign-in and Windows Explorer crashes shown in event logs. Microsoft recommends a temporary workaround of manually launching explorer.exe via Task Manager and has provided a mitigation for enterprises through Known Issue Rollback (KIR) group policies.
read more โ†’

Microsoft named Leader in 2026 Distributed Hybrid MQ

๐ŸŸฆ Microsoft was named a Leader in the 2026 Gartnerยฎ Magic Quadrantโ„ข for Distributed Hybrid Infrastructure, ranking highest for Ability to Execute. The post highlights how Azure Local and Azure Arc deliver a unified approach to manage infrastructure across datacenters, edge, multi-cloud, and sovereign environments. It explains options for sovereignty, disconnected operations, and AI inference at the edge with Foundry Local, emphasizing consistent management and operational simplicity.
read more โ†’

Exposed Vite servers probed for cloud credentials

๐Ÿ”Ž Attackers have begun probing exposed Vite development servers for sensitive data, including AWS and Azure credentials, environment files, and infrastructure state. F5 Labs observed over 32,000 scan attempts in August exploiting a file-access bypass (CVE-2026-39364) that defeats Vite's deny-list protections when specific query parameters are used. F5 urges patching Vite, rotating secrets, and ensuring development servers are not bound to external interfaces.
read more โ†’

Mass scanning of exposed Vite dev servers steals cloud secrets

๐Ÿ›ก๏ธ A large-scale campaign is scanning internet-exposed Vite development servers to extract AWS and Azure credentials by exploiting CVE-2026-39364 in affected Vite versions. F5 detected over 800 attacks and ~32,000 events, observing attackers append parameters like ?raw or ?import&raw to bypass file access controls and retrieve sensitive files. The operation targeted environment files, cloud credential/config files, Terraform and serverless state, and system files, using traversal and encoding tricks for evasion.
read more โ†’

Building Modern Infrastructure Resiliency with Azure

๐Ÿ”’ Microsoft Azure outlines how resiliency must be integrated into modernization efforts, emphasizing design-time planning, continuous assessment, and recovery readiness. The post highlights tools like Azure Infrastructure Resiliency Manager, Azure Chaos Studio, and Azure Backup to reduce blast radius, validate failover, and protect recovery points. It positions resiliency as a continuous operational practice aligned to workload criticality and business outcomes.
read more โ†’

Design framework for zone-resilient Azure workloads

๐Ÿ›ก๏ธ This post argues that zone resiliency should be decided per component rather than applied as a single setting across a workload. It explains Azure availability zones, contrasts service-managed zone redundancy with user-managed zonal designs, and outlines common component categories and when two or three zones are appropriate. The guidance emphasizes validating service-specific behavior, modeling cost and capacity tradeoffs, and documenting failover, capacity, and operational responsibilities.
read more โ†’

Azure as an End-to-End Platform for Enterprise AI

๐Ÿ”’ Microsoft frames Azure as a unified platform enabling enterprise AI in production, emphasizing integration across models, infrastructure, data, applications, and developer tools. The post highlights Azureโ€™s multi-model support, Microsoft Foundry for model choice and operations, and data governance via Microsoft Fabric and Purview. It cites Gartner and Forrester Leader recognitions and customer examples showing modernization and responsible AI deployment.
read more โ†’

GPT-6 Astra brings frontier AI to enterprise Foundry

๐Ÿค– Microsoft announces GPT-6 Astra is rolling out via the Microsoft Foundry Limited Access Program, enabling agentic AI to execute complex work across enterprise applications. Foundry integrates identity, networking, governance, and compliance to help firms move from experiments to production with controls like Entra, encryption, private networking, and role-based access. Astra supports computer-use capabilities, multi-step reasoning, and tool use while Foundry provides safeguards, monitoring, and deployment options.
read more โ†’

Scaling hybrid physical security operations with Azure Arc

๐Ÿ”’ Microsoftโ€™s physical security team combined Azure Arc, Azure Virtual Desktop, and Azure monitoring services to centralize management of thousands of distributed servers while preserving local resiliency and security. The approach standardized patching, configuration, and observability across hybrid environments, saving thousands of hours annually and accelerating image and update rollouts. Integration with monitoring and RBAC improved visibility, compliance, and access control without moving workloads offsite.
read more โ†’

Azure introduces high-performance multicloud interconnect

๐Ÿ”— Azure Multicloud Interconnect simplifies private connectivity between Azure and AWS by providing high-bandwidth, cloud-native links that abstract multicloud networking complexity. It extends to Azure Private Link for an end-to-end private path and offers features such as MACsec security, four-nines availability, and scalable capacities up to 100 Gbps at GA. The collaboration with AWS implements a standardized Open API to enable faster provisioning, operational simplicity, and potential wider interoperability across hyperscalers and carriers.
read more โ†’

AWS launches Interconnect multicloud with Azure preview

๐Ÿ”— AWS has announced the public preview of AWS Interconnect โ€“ multicloud, enabling managed private connections between AWS and Microsoft Azure. The preview expands the multicloud interoperability framework first introduced at re:Invent 2025, which includes an open specification for network interoperability. Azure adoption of the specification provides a single managed experience for customers connecting workloads across AWS and Azure in selected regions.
read more โ†’

Threat actor claims Azure employee data from firms

๐Ÿ›ก๏ธ A threat actor using the alias โ€œTheHatmanโ€ is advertising employee databases allegedly exfiltrated from Microsoft Azure tenants of multiple large companies, claiming a total of 3.64 million records. The posted dumps, beginning July 31, target organizations such as McDonaldโ€™s, Tata Consultancy Services, Gap Inc., Vodafone, HCL, IHG, and Kyndryl and include names, emails, titles, phone numbers, addresses, and tenant account details. Several affected firms say investigations show no evidence of current breaches and that much of the data appears dated and non-sensitive, while cyber intelligence firm Hudson Rock assessed the samples as authentic and noted presence of service and admin accounts that could enable targeted attacks.
read more โ†’

Cavern C2 evolves, abusing DNS and Google Apps

๐Ÿ” Kaspersky researchers uncovered new components of the Cavern (CAV3RN) command-and-control framework used by Iranian-linked operators to target Israeli entities, revealing a module that switches between direct HTTPS and a Google Apps Script relay using DNS A-record responses. The modular toolkit supports extensive post-exploitation functions and minimizes forensic visibility, while additional reports show HOLLOWGRAPH abusing Microsoft 365 calendars and DNS tunneling to maintain and refresh Azure AD credentials. The findings highlight a shift to a plugin-based architecture and continued use of legitimate services to evade detection.
read more โ†’

AWS DataSync Enhanced Mode Adds HDFS, Azure Blob

๐Ÿ› ๏ธ AWS DataSync Enhanced mode now supports agent-based transfers for HDFS, Microsoft Azure Blob Storage, and self-managed object storage, and agents can be deployed on Microsoft Hyper-V. Using a DataSync agent, customers can move data with Enhanced mode's parallelism, unlimited file counts, and detailed metrics. HDFS support includes multiple NameNode high-availability configurations and Transparent Data Encryption with Kerberos authentication for secure, compliant migrations.
read more โ†’

Amazon Connect adds audio optimization for Azure VDI

๐ŸŽง Agents using Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take Amazon Connect calls directly from their virtual desktop with audio optimization enabled. IT administrators perform a one-time setup to redirect media from the virtual desktop to the agent's local device, improving call audio quality. Agents access calls via the Amazon Connect Customer agent workspace or custom interfaces built with the Amazon Connect Customer open-source JavaScript libraries. This capability complements existing support for Amazon WorkSpaces, Citrix, and Omnissa cloud desktops and is available in all AWS Regions offering Amazon Connect Customer except AWS GovCloud (US-West).
read more โ†’

Security Hub expands to AI protections and Azure

๐Ÿ”’ Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more โ†’