< ciso
brief />
Tag Banner

All news with #microsoft tag

942 articles · page 3 of 48

Advancing Zero Trust for AI: New Tools and Guidance

🔒 Microsoft expands its Zero Trust for AI strategy with an automated Zero Trust Assessment and a new DevSecOps pillar in the Zero Trust Workshop to help organizations secure AI agents, developer workflows, and CI/CD pipelines. The Assessment evaluates tenant configuration and activity across Identity, Devices, Network, Data, AI, Security Operations, and Infrastructure, producing prioritized recommendations and executive-ready reports. The DevSecOps pillar maps Zero Trust principles into 15 control groups and 91 tasks covering source code, pipelines, dependencies, artifacts, and infrastructure-as-code. Together, the Assessment and Workshop convert findings into a phased 12–24 month remediation roadmap.
read more →

Microsoft Defender: Device Isolation Stops Ransomware Fast

🚨 Microsoft Defender’s attack disruption now includes device isolation, an automated response that isolates compromised endpoints. At QNET, Defender detected a multi-stage attack using mshta.exe and enforced isolation within 128 seconds, blocking a second-stage payload and preventing persistence or lateral movement. This action is AI-driven, time-limited, operator-controlled, and designed to work with user containment to reduce risk and speed SOC response.
read more →

RDS for SQL Server BYOM expands to 10 regions

📢 Amazon RDS for SQL Server now supports Bring Your Own Media (BYOM) in 10 additional commercial AWS Regions, including locations across Asia Pacific, Europe, and Mexico. BYOM lets customers reuse existing Microsoft SQL Server licenses with active Software Assurance via Microsoft's License Mobility program. The feature supports SQL Server 2019, 2022, and 2025 and integrates with AWS License Manager to track license usage and help maintain compliance. Availability and pricing vary by region.
read more →

Critical Cosmos DB flaw exposed master key risk

🛡️ A security researcher discovered a critical vulnerability in Azure Cosmos DB's Gremlin API that could have exposed the Cosmos Master Key, granting attackers read/write access to any Cosmos account and revealing database identifiers. Wiz, a Google subsidiary, disclosed the issue to Microsoft in November 2025; Microsoft pushed a hot fix within two days and later re-engineered the service to remove the master key and add guardrails. This follows a prior 2021 finding where Cosmos DB keys were exposed via a Jupyter Notebook flaw.
read more →

Microsoft Security: July 2026 innovations and updates

🔒 Microsoft announced new AI-native security capabilities across Defender, Entra, Purview, and Intune to help organizations secure AI environments, accelerate SecOps, and protect data and identities. Highlights include Project Perception, expanded Defender protections like prompt injection blocking, tenant governance and passkey defaults in Entra, Purview network-level DLP for shadow AI apps, and Intune Suite inclusion in Microsoft 365 E5 to strengthen endpoint management.
read more →

Russian hackers exploit Exchange OWA to hijack mailboxes

📧 A Russia-aligned group, tracked as TA488 (Void Blizzard/Laundry Bear), began a campaign on July 22 using a “half-click” exploit in Microsoft Exchange Outlook Web Access to install a browser-based backdoor when recipients viewed specially crafted emails. The attackers abused CVE-2026-42897, a cross-site scripting flaw allowing JavaScript to run inside OWA without clicking links or opening attachments. The implant, named OWAReaper, removes evidence from stored messages, harvests account data, and can leverage Outlook add-ins to obtain OAuth tokens and owner-level mailbox access, creating server-side persistence that typical endpoint-focused defenses may miss.
read more →

Windows 11 KB5101684 preview brings 42 fixes

🔔 Microsoft released the optional KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, delivering 42 bug fixes and incremental feature rollouts. This non-security monthly preview updates systems to builds 26100.8973 and 26200.8973 and is installable via Settings > Windows Update or the Microsoft Update Catalog. Notable changes include File Explorer improvements, Voice Isolation for Voice Access, enhanced Windows Hello ESS support for external fingerprint readers, and fixes for File History and MDM enrollment issues. The update is optional and currently has no known issues.
read more →

Long-Lived Vulnerability in Microsoft Secure Boot

🔒 Microsoft’s Secure Boot contained a persistent weakness for most of its lifespan, researchers found. ESET analysts discovered 11 signed firmware images, including at least one from 2013, that were defective yet remained publicly signed. These images, known as shims, were intended to extend Secure Boot to Linux and utility software but can be abused to bypass protections via UEFI. The flaw arose because Microsoft failed to revoke the vulnerable shims after the defects were identified.
read more →

Best Buy scales secure AI access with federation

🔒 Best Buy eliminated service account key hassles by adopting Google Cloud's Workforce Identity Federation to let developers use their existing Microsoft Entra ID credentials for secure access to BigQuery and other cloud services. This syncless approach removes the need to synchronize user records into Cloud Identity, reduces credential management and attack surface, and delivers auditable, user-level access. The change is largely invisible to developers while simplifying operations for security and platform teams.
read more →

Microsoft unveils agentic AI security platform

🛡️ Microsoft revealed Project Perception, MAI-Cyber-1-Flash and several AI security initiatives during a July 27 Security launch preview. Project Perception uses coordinated red, blue and green agents to identify, triage and remediate threats, and will enter Preview on August 3. The company also introduced the MAI-Cyber-1-Flash model integrated into MDASH, plus the FORGE Lab and the External Red Team Alliance to accelerate offensive research and broaden AI safety efforts.
read more →

NVIDIA Leads New Open Secure AI Alliance Initiative

🛡️ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more →

Microsoft unveils MDASH cybersecurity model update

🛡️ Microsoft introduced MAI-Cyber-1-Flash inside its MDASH multi-model vulnerability harness, claiming a 95.95% CyberGym score when paired with GPT-5.4 and a 50% cost reduction versus its previous MDASH mix. The new model is limited to MDASH private preview through Azure AI Foundry and is not available as a standalone API. Microsoft says MAI-Cyber-1-Flash handles up to 90% of tasks while GPT-5.4 addresses the hardest 10%, but the headline score applies to the MDASH configuration rather than the model alone.
read more →

Microsoft unveils multi-model agentic cyber stack

🔐 Microsoft announced Project Perception, an AI-driven service entering public preview on Aug. 3 that uses multiple AI agents to continuously evaluate and update enterprise security posture. The multi-model harness selects the best model for each task to balance quality and cost, and Microsoft also introduced MAI-Cyber-1-Flash, a specialist model trained to find vulnerabilities. Integrated agents perform red-, blue- and green-team playbooks to detect, triage, and remediate threats automatically.
read more →

NVIDIA leads 37-member Open Secure AI Alliance

🔒 NVIDIA and 36 organizations have launched the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and AI agents. The group spans cloud, security, enterprise software, and AI companies including Microsoft, Cisco, CrowdStrike, Hugging Face, IBM, and the Linux Foundation. The alliance’s scope covers identity, permissions, isolation, guardrails, logs, model formats, scanning, and secure coding workflows. Its first technical contribution is NVIDIA-labs OO Agents (NOOA), an Apache 2.0 research framework to test, trace, audit, and govern agent behavior.
read more →

Rethinking Security for the Age of AI

🛡️ Microsoft introduces Project Perception, an agentic security system designed for AI-era threats. It combines signals, context, models and specialized agents to continuously perceive, reason and act at machine speed while keeping humans in control. The system uses a multi-model architecture to optimize for quality and cost, beginning with software vulnerability management using MAI-Cyber-1-Flash in MDASH. Project Perception enters public preview on August 3.
read more →

Microsoft launches global AI red teaming alliance

🛡️ Microsoft announces the External Red Team Alliance (EXTRA) to broaden AI safety testing by funding and coordinating external academic and operational expertise across six continents. The initiative provides unrestricted gifts to 18 university labs and builds a distributed network of specialists to address multilingual, domain-specific, and regional AI risks. EXTRA aims to advance evaluation methodologies and strengthen collaboration between academia, practitioners, and industry to better identify and mitigate emerging threats in frontier AI systems.
read more →

Microsoft Databases: Reliability and AI Readiness

🟦 Customer feedback and PeerSpot recognitions highlight five priorities for Microsoft Databases: reliability, scalability, operational simplicity, developer productivity, and AI readiness. Reviews from SQL Server, Azure SQL Database, Azure Cosmos DB, and Azure Database for PostgreSQL users emphasize uptime, ease of migration, performance, and integration with Azure services. These insights guide Microsoft’s investments to help customers modernize and build AI-powered applications while maintaining security and governance.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

Microsoft 365 outage blamed on maintenance bug

🔧 Microsoft attributed the large July 23 outage to a bug in its automated network maintenance request system that removed IP routes from more devices than intended, disrupting Azure and Microsoft 365 services, especially for customers routed through the West US region. The incident began at 10:44 AM ET and was resolved after a rollback completed at 2:26 PM ET, with full recovery of all services by 3:41 PM ET. Microsoft is conducting a full internal review and will publish a final post-incident report.
read more →

AT&T and Microsoft scale trillion‑token AI workloads

🤝 AT&T partnered with Microsoft Foundry and AMD to build OTel2.0, a telecom-focused AI stack that processes massive token volumes while controlling cost and complexity. Using Foundry Managed Compute and a mix of open models such as Phi-4, OSS-120B, and Gemma-4, AT&T scaled across heterogeneous GPUs (including AMD MI300X) to run experiments, data preparation, and training—processing about 1T tokens and leveraging ~530 GPUs. The effort prioritized rapid deployment, model choice, and economic efficiency.
read more →