Cloud Security
The latest Cloud Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-53723: Hyper‑V Truncation Bug Hands Local Attackers SYSTEM Control
Microsoft has published an advisory for a new elevation‑of‑privilege vulnerability in Windows Hyper‑V that could allow an authorized attacker on an affected host to escalate privileges and take...
Azure VMs Hit by CVE-2025-53781: Information Disclosure Risk Prompts Urgent Patching
Microsoft has published a security advisory for CVE-2025-53781, warning Azure Virtual Machines users of a critical information disclosure vulnerability that could allow attackers to siphon sensitive...
AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats
At Black Hat USA 2025, Zenity Labs peeled back the curtain on a threat that security teams have long feared but rarely seen weaponized at scale: zero-click prompt injection attacks that silently...
CSPM and Server Plan 2 Hit Azure Government, Closing a Critical Feature Gap for Defense Workloads
Microsoft has finally delivered full parity for its Defender for Cloud security platform in U.S. sovereign clouds, ending a long wait for federal agencies and defense contractors. As of this month,...
Microsoft Probes Unit 8200 Azure Surveillance as Executives Doubt Israel Staff Transparency
Microsoft is conducting an internal investigation into how Israel’s elite military intelligence unit used Azure cloud services for large-scale surveillance of Palestinians, amid rising concerns...
Azure’s Basic IP Retirement Forces Sophos Firewall to Standard SKU: Deployment Guide & Best Practices
As of September 30, 2025, Microsoft officially retired Basic SKU public IP addresses, and for anyone deploying Sophos Firewall in Azure, the message is clear: you must use Standard SKU public IPs for...
NTT DATA Launches Global Microsoft Cloud Unit to Fast-Track Agentic AI in Enterprise
NTT DATA has formally launched a global business unit dedicated to Microsoft Cloud, aiming to accelerate enterprise adoption of agentic AI and cloud modernization—a move backed by nearly 100 client...
CISA Mandates Immediate Disconnect of EOL Exchange Servers After Black Hat Exploit Demo for CVE-2025-53786
A critical Microsoft Exchange Server vulnerability now carries a binding directive from the U.S. Cybersecurity and Infrastructure Security Agency, following a live demonstration of the exploit at the...
Barracuda SecureEdge Targets Windows SMBs with Azure-Backed SASE and Zero-Trust Access
Barracuda Networks is making a determined push into the SASE market with a platform explicitly tailored for small and mid-sized businesses that live inside the Microsoft ecosystem. SecureEdge, the...
Microsoft Azure Hosted Israeli Military Surveillance of Palestinian Calls as War Deepened
Unit 8200, Israel's elite signals intelligence corps, built and operated a mass surveillance system atop Microsoft Azure that collected and stored recordings of millions of Palestinian phone calls,...
Microsoft Patches CVE-2025-53787: BizChat Flaw Exposes Enterprise AI Chat Data
Microsoft has confirmed a new vulnerability, CVE-2025-53787, that allows potential information disclosure through the BizChat feature of Microsoft 365 Copilot, sparking urgent patch deployment across...
Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets
A newly disclosed vulnerability in Microsoft 365 Copilot BizChat can expose sensitive business information without any user interaction, Microsoft warned in a security advisory published this week....