#azure
13 stories taggedazure.

Microsoft Pins Azure Wipeout on JadePuffer, the First Agentic Ransomware Crew
Storm-3168's AI-driven agents destroyed more than 100 Azure storage accounts in seven minutes, using a service principal whose credentials had been sitting in a public GitHub issue.

Microsoft Publishes a Cloud Web App Attack Playbook and Names the Weak Spots Nobody Wants to Own
Microsoft's new threat matrix organises how attackers actually break into cloud-hosted web apps, from forgotten DNS records to Kudu consoles left facing the internet.

Attackers Are Scanning Exposed Vite Dev Servers to Steal AWS and Azure Keys
A month-long campaign hunted cloud credentials on internet-facing Vite servers using a file-read bypass disclosed in April.

Cloud Security Isn't One Problem. It's Three.
A new Intruder study of 3,000 organisations finds AWS, Azure, and Google Cloud fail in different ways, and one checklist won't catch them all.

Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.
Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out fast enough, and is pushing a network-level defensive layer to buy time.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Azure Cloud Data Breach Affects Major Companies
A threat actor used stolen credentials to pull millions of employee records from well-known brands

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

Azure Cosmos DB Flaw Let Researchers Reach Any Customer's Database
Wiz says its CosmosEscape exploit chain broke out of a query sandbox and grabbed a master key that unlocked databases across Microsoft's cloud. Microsoft has patched it.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

Accenture confirms break-in as hacker offers 35GB of stolen code for sale
The consulting giant says the incident is contained, but a forum seller known as 888 claims to be holding source code, Azure access keys and SSH keys taken in July 2026.

Microsoft Pulls Post-Quantum Deadline Forward to 2029
Azure CTO Mark Russinovich says the 'risk horizon' has moved. Redmond now wants PQC-ready systems four years ahead of the industry's 2033 target.

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached
Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.