< ciso
brief />
Tag Banner

All news with #microsoft azure tag

72 articles

Threat actor claims Azure employee data from firms

🛡️ A threat actor using the alias “TheHatman” is advertising employee databases allegedly exfiltrated from Microsoft Azure tenants of multiple large companies, claiming a total of 3.64 million records. The posted dumps, beginning July 31, target organizations such as McDonald’s, Tata Consultancy Services, Gap Inc., Vodafone, HCL, IHG, and Kyndryl and include names, emails, titles, phone numbers, addresses, and tenant account details. Several affected firms say investigations show no evidence of current breaches and that much of the data appears dated and non-sensitive, while cyber intelligence firm Hudson Rock assessed the samples as authentic and noted presence of service and admin accounts that could enable targeted attacks.
read more →

Cavern C2 evolves, abusing DNS and Google Apps

🔍 Kaspersky researchers uncovered new components of the Cavern (CAV3RN) command-and-control framework used by Iranian-linked operators to target Israeli entities, revealing a module that switches between direct HTTPS and a Google Apps Script relay using DNS A-record responses. The modular toolkit supports extensive post-exploitation functions and minimizes forensic visibility, while additional reports show HOLLOWGRAPH abusing Microsoft 365 calendars and DNS tunneling to maintain and refresh Azure AD credentials. The findings highlight a shift to a plugin-based architecture and continued use of legitimate services to evade detection.
read more →

AWS DataSync Enhanced Mode Adds HDFS, Azure Blob

🛠️ AWS DataSync Enhanced mode now supports agent-based transfers for HDFS, Microsoft Azure Blob Storage, and self-managed object storage, and agents can be deployed on Microsoft Hyper-V. Using a DataSync agent, customers can move data with Enhanced mode's parallelism, unlimited file counts, and detailed metrics. HDFS support includes multiple NameNode high-availability configurations and Transparent Data Encryption with Kerberos authentication for secure, compliant migrations.
read more →

Amazon Connect adds audio optimization for Azure VDI

🎧 Agents using Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take Amazon Connect calls directly from their virtual desktop with audio optimization enabled. IT administrators perform a one-time setup to redirect media from the virtual desktop to the agent's local device, improving call audio quality. Agents access calls via the Amazon Connect Customer agent workspace or custom interfaces built with the Amazon Connect Customer open-source JavaScript libraries. This capability complements existing support for Amazon WorkSpaces, Citrix, and Omnissa cloud desktops and is available in all AWS Regions offering Amazon Connect Customer except AWS GovCloud (US-West).
read more →

Security Hub expands to AI protections and Azure

🔒 Security Hub now adds native AI workload protection and Microsoft Azure monitoring to centralize enterprise security across clouds. It discovers Azure resources, evaluates posture against CIS benchmarks, and prioritizes findings alongside AWS signals using the same formats and workflows. New GuardDuty AI Protection detects anomalous model invocations and cost-harvesting, while AI-powered investigations accelerate triage. A continuous AI inventory catalogs models and agents across accounts, and Security Hub Extended integrates 21 curated partners to broaden coverage.
read more →

Novel OAuth Client ID Spoofing Targets Cloud

🔒 Cyber-attackers are increasingly using OAuth client ID spoofing to access cloud environments by abusing Microsoft Entra ID (formerly Azure AD). Proofpoint researchers found threat actors issuing ROPC token requests to the OAuth 2.0 endpoint, producing AADSTS error codes that reveal valid usernames and authentication controls. The technique produces blank or spoofed application IDs in Entra sign‑in logs, making detection difficult and enabling large-scale campaigns targeting millions of accounts.
read more →

Smart Tiered Cache for public cloud regions

🔧 Smart Tiered Cache now supports public cloud regions by accepting a user-provided region hint. Cloudflare maps ambiguous anycast or regional unicast origins to the correct cloud region so it can select optimal primary and fallback upper tiers, improving cache efficiency and reducing hairpin latency. The feature is available via dashboard, API, and Terraform and initially supports AWS, GCP, Azure, and Oracle Cloud.
read more →

AWS Systems Manager adds Azure VM multicloud support

🛠️ AWS Systems Manager now connects to Azure Virtual Machines without manual agent installs or per-node advanced tier fees. Create a Cloud Connector to deploy the SSM Agent at scale so Azure VMs appear alongside EC2 in a unified console. Manage them with Session Manager, Automation, Run Command, State Manager, Patch Manager, and Inventory from a single workflow. Advanced Instances Tier is removed; pay-as-you-go for non-EC2 session and command usage begins Sept 30, 2026.
read more →

Meet Brain: Azure’s AI system for reliability

🔎 Brain is Azure’s centralized AIOps cloud health intelligence system that forms a real-time digital twin with Azure Resource Graph. It fuses telemetry, AI/ML models, service topology, and customer impact into unified health determinations that drive notifications, deployment safeguards, and outage declarations. This post introduces Brain’s design, inputs and outputs, and how it enables faster, more consistent reliability actions across Azure.
read more →

Designing Azure IaaS for Long-Term Cost Efficiency

🔍 This third post in the Azure IaaS series outlines best practices to design, build, and optimize cloud infrastructure for sustained cost efficiency. It explains how compounded architectural choices across compute, storage, and networking drive costs and offers Azure capabilities—such as VM families, automated tiering, and resilient networking—to align resources with workload needs and reduce TCO.
read more →

AWS Security Hub Adds Microsoft Azure Monitoring

🔒 AWS Security Hub now monitors Microsoft Azure resources, extending risk analytics, cloud security posture management, vulnerability management, and security response across both clouds. The service auto-discovers Azure VMs, ACR images, Function Apps, and identities, evaluating misconfigurations, internet exposure, and software vulnerabilities. Findings from AWS and Azure appear in a single prioritized view with consistent formats and automation workflows, and a 30-day free trial for Azure monitoring is available.
read more →

Claude in Microsoft Foundry Now Generally Available

🛠️ Claude in Microsoft Foundry is now GA on Azure, offering enterprises an integrated path from experimentation to production. Hosted on Azure and running on NVIDIA Blackwell Ultra systems, Claude provides frontier model capabilities while integrating with enterprise controls like Entra ID, RBAC, governance, and data residency. Developers can use the Messages API, prompt caching, extended thinking, and tool streaming, and teams can opt for zero data retention for high-sensitivity workloads. Billing is consolidated as Claude Consumption Units (CCU) on the Azure bill for simplified procurement.
read more →

Cloud bucket hijacking risks across major providers

🔒 Unit 42 researchers describe a bucket hijacking technique that exploits globally unique storage bucket names across major cloud providers. By deleting a target bucket and recreating it under an attacker-controlled account with the same name, data streams (logs, Pub/Sub, replication, transfer jobs, etc.) can be silently rerouted to an adversary. The team validated the attack across Google Cloud, AWS and demonstrated cross-subscription scenarios in Azure, and has shared findings with the affected vendors.
read more →

Plan and Migrate Data with Azure Storage

📌 This blog explains a structured approach to enterprise storage migration using Microsoft tools. It emphasizes planning, assessment, and choosing the right migration path based on data volume, connectivity, and downtime tolerance. Key solutions covered include Azure Migrate, Azure Storage Mover, Azure Data Box, and a preview Azure Copilot Migration Agent. The post illustrates phased strategies, real customer examples, and guidance for regulated and AI use cases.
read more →

AWS launches free 500 Mbps multicloud Interconnect

🔌 AWS now offers a free 500 Mbps Interconnect - multicloud tier to simplify private connectivity between AWS and other public clouds. The open specification behind Interconnect is already adopted by Google Cloud and Oracle Cloud Infrastructure, with Microsoft Azure planned later in 2026. The free tier provides a fully managed, resilient path (one local Tier 1 Interconnect per customer per region) and includes an Amazon CloudWatch Network Synthetic Monitor at no additional cost. Other CSPs set their own charges for their side of the link, so customers should review third-party pricing before creating an Interconnect.
read more →

Azure enables seamless cross-cluster networking for AKS

🚀 Microsoft announces the public preview of cross-cluster networking for Azure Kubernetes Fleet Manager, bringing transparent east‑west multi-cluster connectivity powered by Advanced Container Networking Services. Built on Cilium and Kubefleet, this managed capability extends the Kubernetes networking model across clusters to enable direct pod-to-pod communication, policy enforcement, and observability while preserving cluster isolation. The managed approach reduces operational overhead for multi-cluster fleets and supports resilient, global, and shared‑services architectures.
read more →

Azure NetApp Files advances EDA performance at scale

🚀 Azure NetApp Files extends cloud storage performance for Electronic Design Automation (EDA) by delivering predictable, high-throughput shared storage at massive concurrency. New capabilities like large volumes and breakthrough mode enable thousands of parallel jobs with consistent latency, validated by SPECstorage® Solution 2020 EDA_BLENDED benchmarking. Leading semiconductor firms are adopting ANF for production EDA workloads.
read more →

Azure Files Entra-Only Identities Advance Cloud Security

🔐 Microsoft has reached general availability for Entra-Only identities for Azure Files SMB, enabling native Microsoft Entra ID authentication for SMB file shares using cloud-only identities. This eliminates the need for on-premises Active Directory, Entra Connect, or managed domain controllers, simplifying architecture and reducing operational overhead. Entra acts as the Kerberos Key Distribution Center (KDC), issuing Kerberos tickets while preserving SMB protocol compatibility, and supports VDI scenarios with FSLogix, Managed Identities, macOS clients, and NTFS ACL editing. The capability is supported across HDD and SSD shares, available at no extra cost, and is being extended to sovereign cloud regions.
read more →

Microsoft's Investments Drive PostgreSQL's Cloud Future

🔧Microsoft outlines its sustained investment in PostgreSQL through upstream contributions, managed services, developer tools, and community programs. The post highlights 345 commits to the latest PostgreSQL release, active Microsoft committers working upstream, and service offerings such as Azure Database for PostgreSQL and Azure HorizonDB. It also emphasizes AI integrations like vector search and model invocation alongside IDE tooling and community engagement.
read more →

Microsoft and SAP Advance Enterprise AI on Azure, Sapphire

🚀 At SAP Sapphire 2026, Microsoft and SAP announced expanded integrations to embed AI across SAP applications on Azure, emphasizing Microsoft IQ as a shared intelligence layer and agent-to-agent capabilities between Copilot and Joule. The updates include bi-directional, zero-copy delta sharing with SAP Business Data Cloud and Microsoft Fabric, sovereign cloud expansions, and an enlarged RISE with SAP acceleration program. These developments aim to move enterprises from experimentation to production-ready, governed AI at scale.
read more →