Predictive Shielding FTW! Defender XDR now anticipates attacker moves and hardens paths proactively. Enable it for cross-cloud protection. #ThreatIntelligence #AzureSecurity
Predictive Shielding FTW! Defender XDR now anticipates attacker moves and hardens paths proactively. Enable it for cross-cloud protection. #ThreatIntelligence #AzureSecurity
Azure's OpenAI from 2021 until almost the end of 2023 was allowed to actually use your data for training, even if they said it wasn't, including in a GCC environment (Government Cloud Computing). So yes, OpenAI effectively has gigabytes worth of classified information that you can just ask for due to companies like Ask Sage. Crazy how OpenAI gets rewarded for this, while whistleblowers get hunted down.
#openai #AI #AzureSecurity #azure
I wrote a new blog post based on my talk on #CloudBrew2025.
https://vasenius.fi/how-to-secure-ai-services-to-comply-with-eu-ai-act-in-azure/
New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
Read the blog 👉 https://marshsecurity.org/sentinel-saturday-using-tasks-with-automation/
In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.
Most teams aren’t getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.
- Auto-create tasks when automation fails (so nothing slips through the cracks)
- Auto-complete tasks when automation succeeds
- Use tasks to verify automation outcomes
- Build engineering feedback loops and automation #QA
Read the blog 👉 https://marshsecurity.org/sentinel-saturday-using-tasks-with-automation/
#MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
#CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
#CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations
🛡️ CVE-2025-12479 (CRITICAL, CVSS 10): Azure Access BLU-IC2/IC4 (≤1.19.5) lack CSRF tokens, allowing full remote compromise—no patch yet. Apply WAFs, enforce header checks, and restrict access. https://radar.offseq.com/threat/cve-2025-12479-cwe-352-cross-site-request-forgery--adbd5512 #OffSeq #Vuln #CSRF #AzureSecurity
🚨 CRITICAL: CVE-2025-12423 (CVSS 10) in Azure BLU-IC2 & IC4 (≤1.19.5) allows remote DoS via protocol manipulation (CWE-248). No patch yet—apply filtering, segment networks, and monitor logs. Stay proactive! https://radar.offseq.com/threat/cve-2025-12423-cwe-248-uncaught-exception-in-azure-9b7c3217 #OffSeq #AzureSecurity #CVE2025 #BlueTeam
🔴 CVE-2025-12424 (CRITICAL): Azure Access BLU-IC2 & BLU-IC4 (≤1.19.5) affected by SUID-bit privilege escalation flaw. No patch yet — restrict & monitor SUID binaries now to prevent full compromise. Details: https://radar.offseq.com/threat/cve-2025-12424-cwe-269-improper-privilege-manageme-ac110a5f #OffSeq #AzureSecurity #CVE #UnixSec
Microsoft Warns of Escalating Attacks on Azure Blob Storage, Urges Tighter Security
#Azure #Cybersecurity #Microsoft #CloudSecurity #InfoSec #DataBreach #ThreatIntel #Cloud #MicrosoftAzure #DevSecOps #AzureSecurity
I wrote a brief Playbook, how to get started with securing the Azure AI Service's in your environment. Azure AI services provides multiple layers of security that you should consider when implementing a solution, which I present in this blog post:
https://vasenius.fi/example-playbook-to-secure-your-azure-ai-services/
A seemingly harmless Chrome extension can now hijack your digital keys—stealing Azure session cookies and bypassing MFA. Curious how this stealthy Cookie-Bite attack works and what you can do to stay secure?
https://thedefendopsdiaries.com/understanding-and-mitigating-the-cookie-bite-attack/
#cookiebiteattack
#azuresecurity
#sessioncookies
#cyberthreats
#microsoft365security
New Open-Source Tool Spotlight 🚨🚨🚨
Blacksmith is a cloud-native adversary simulation tool that scales offensive testing in Azure. It’s built to automate simulation setups, leveraging Azure services like Sentinel for detection validation. Useful for red teaming and continuous security improvement.
🔗 Project link on #GitHub 👉 https://github.com/OTRF/Blacksmith
#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity
— ✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴☠️
Elevate access to manage all Azure subscriptions and management groups now in Public Preview https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin
#azure #entra #microsoft #cloudmanagement #azuresubscriptions #cloudsecurity #azuresecurity #azureadmin #publicpreview
In this blog, I have demonstrated step by step instructions on implementing Azure Disk encryption for VM disks.
#DataSecurity #DiskEncryption #CloudSecurity #AzureDiskEncryption #AzureSecurity #Azure #Cloud
As part of AZ-500 learning, I explored Container Registry and Azure Kubernetes Service and shared the step by step instructions on how to implement these in Azure.
Read the blog here and let me know your thoughts:
#CloudSecurity #Azure #AzureKubernetes #AzureSecurity #Containers #Docker #kubernetes
Azure Blunder: Microsoft’s Airflow Integration Opens Door to Cyber Mischief!
Discover the low-severity flaws in Azure Data Factory that could let attackers play secret admin. Are your Kubernetes clusters safe? #AzureSecurity
https://thenimblenerd.com/?p=1033097
Attacking Entra Metaverse: Part 1
https://posts.specterops.io/attacking-entra-metaverse-part-1-c9cf8c4fb4ee
Does anybody have experience with Cloudbreach.io’s Breaching Azure training? Is it worth the investment? #BreachingAzure #Cloudbreach #OffensiveAzureSecurity #AzureSecurity
Looks like #Microsoft forgot to register the domains listed in their SDK, which has now been taken over
https://xcancel.com/watchtowrcyber/status/1846137686832369889?s=61&t=RPbY9cLDkgmEACY4rfxmfA
Azure Kubernetes Clusters Vulnerable To Sneaky TLS Bootstrap Attack
Today, we're diving into the world of cybersecurity and exposing a sneaky attack that has been targeting Azure Kubernetes Clusters. That's right, your beloved cloud platform may not be as secure as you think!
#Azure #Kubernetes #CyberSecurity #Vulnerability #KubernetesAttack #TLSBootstrap #AzureSecurity #CloudSecurity #DataProtection #Hack #MicrosoftAzure #AzureKubernetesService #InfoSec #CyberAttack
https://cloudhosting.evostrix.eu/azure-kubernetes-clusters-vulnerable-to-sneaky-tls-bootstrap-attack/
Are your Azure Storage Accounts locked down to a network? Are you still resisting Private Endpoints? Keep your data secure #AzureSecurity #ConfigurationMonitoring #MicrosoftSentinel