Cloud Security
The latest Cloud Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Copilot's Policy Flaw Allows Blocked AI Agents to Resurface, Creating Governance and Audit Nightmares
Enterprise administrators who thought they had locked down Microsoft 365 Copilot agents are discovering that tenant-wide "No users can access" settings have been silently ignored for certain agents,...
Atturra’s Microsoft Credentials Grow: Six Solution Partner Badges and a Private Cloud Claim to Prove
Atturra has locked in all six Microsoft Solutions Partner designations, but its reported status as Australia’s first Private Cloud Solution Partner remains a single-source claim awaiting official...
Microsoft Forges a Hardware Security Stack for Azure: Custom DPU, Local HSM, and Post-Quantum Roots of Trust
Microsoft is embedding security directly into the silicon that powers Azure, rolling out custom data processing units, server-embedded hardware security modules, and an open-source root of trust...
Hot Chips 2025: Microsoft Unveils Azure Integrated HSM and Open-Source Caliptra 2.0 Root of Trust
At Hot Chips 2025, Microsoft pulled back the curtain on a fundamental redesign of Azure’s hardware security, revealing a custom security ASIC called Azure Integrated HSM and an open-source silicon...
Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook
Organizations relying on Microsoft Copilot's agent policies to restrict AI access are confronting a stark reality: the controls have been breaking silently. In recent weeks, multiple independent...
How Metadata-Driven Zero Trust on Azure Reinforces AI Pipelines Against Modern Attacks
Microsoft’s Azure platform now offers a battle-tested blueprint for locking down machine learning operations using a metadata-driven zero-trust architecture—one that InfoWorld contributor Vikram...
Critical Copilot Audit Flaw Fixed Silently as Governance Issues Mount
Microsoft has patched a critical flaw in Microsoft 365 Copilot that allowed attackers to access and summarize enterprise files without leaving any trace in audit logs—and did so without notifying...
Microsoft Copilot’s ‘No Link’ Prompt Trick Caused Monthslong Audit Log Gaps, No Customer Warning
Microsoft 365 Copilot silently suppressed document access records for months whenever users asked it to summarize a file without including a source link, leaving security teams with empty audit...
Microsoft's Enterprise AI Blueprint: Copilot Everywhere, Custom Silicon, and the Battle for Trust
Microsoft’s AI platform has evolved from a research-driven experiment into a full-fledged enterprise strategy that embeds generative intelligence across every layer of its stack. The Redmond giant...
Microsoft Silently Patches Copilot Audit Blind Spot That Allowed Silent Data Exfiltration
Microsoft quietly fixed a critical gap in Microsoft 365 Copilot’s audit logging in mid‑August 2025 after researchers proved that a simple prompt tweak could make the AI assistant summarize...
Zscaler CEO's 'Wonderful AI' Remarks Ignite Customer Log Training Controversy—Company Denies Using Private Data
Zscaler CEO Jay Chaudhry set off a firestorm when he boasted that the company harnesses over half a trillion daily transactions—including full URLs and proprietary logs—to train its AI models,...
CVE-2025-53763: Microsoft Flags Azure Databricks Privilege Escalation Flaw, Urges Immediate Defensive Actions
Microsoft has disclosed a new privilege escalation vulnerability in Azure Databricks, tracked as CVE-2025-53763, which could allow an attacker with network access to elevate their privileges within...