#azure

52 posts · Last used 6d

Back to Timeline
Jobs for Developers @jobsfordevelopers@mastodon.world · 6d ago
0
0
0
PSConfEU @psconf.eu@bsky.brid.gy · Aug 06, 2026

🔑 Still storing client secrets in your CI/CD pipelines? There’s a better way.

@powers-hell.com@bsky.brid.gy demonstrates how Workload Identity Federation enables #Azure #DevOps and #GitHub Actions to access Azure resources without passwords, secrets, or certificates.

👉 youtu.be/MhuEm98VUWE?si=Xzv...

  • YouTube
0
0
0
Kukmetz @Kukmetz@social.vivaldi.net · Aug 04, 2026
Replying to @voorstad@mastodon.nl
@voorstad@mastodon.nl #Threema uses OpenStreetMap for years. All traffic of the #Signal goes over the Clouds of Amazon, Google, Microsoft & Cloudflare - they only talk about "third partys"! Especially in combination with US (Spy) #CloudAct https://en.wikipedia.org/wiki/CLOUD_Act And even more worse: #Google #Amazon & #Microsoft work together with #Palantir Google "This is about bringing together the best of AI, which Google clearly represents, and enabling our customers to turn their data into decisions, and those decisions into sustainable, competitive advantage." https://www.palantir.com/partnerships/google-cloud/ Amazon #AWS "We're excited to be working with Palantir to make this suite of tools available on AWS and help our customers get to insights faster, unlocking the data they already have. Using AWS, Palantir's ERP suite can help customers offload the complexity, gain faster intelligence from their data, and make critical decisions to save time and expense." https://www.palantir.com/partnerships/aws/ Microsoft #Azure "Organizations around the world will be able to make their data more actionable by using Palantir's platform for data-driven operations and decision making, powered by Azure's cloud-scale analytics and comprehensive AI services." https://www.palantir.com/partnerships/microsoft/ Get it or die stupid = there are no "free" Messenger in this world!
0
1
0
Hackread.com @Hackread@mstdn.social · Jul 30, 2026
📣🚨 The #CosmosEscape vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack. Listen/Read: https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/ #Cybersecurity #Microsoft #Azure #CosmosDB #Vulnerability
0
0
2
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
Discover the Microsoft AI earnings 2026 report. Azure revenue soars as Copilot surpasses 30 million users, driving a new era of agentic digital workforce. #Microsoft #AI #CloudComputing #Azure #Copilot #Earnings #TechNews https://securityexpress.info/microsoft-ai-earnings-2026/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
OffSequence @offseq@infosec.exchange · Jul 31, 2026
CosmosEscape: CRITICAL flaw in Azure Cosmos DB exposed primary keys, granting full DB access. No CVE or mitigation yet. Monitor access keys and watch for official fixes. https://radar.offseq.com/threat/critical-flaw-led-to-azure-cosmos-db-pwnage-79bd9e6a4135bd53 #OffSeq #Azure #CloudSecurity #Vulnerability
0
0
0
OffSequence @offseq@infosec.exchange · Jul 31, 2026
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 30, 2026
🤖 CosmosEscape: Azure Cosmos DB flaw (patched) let attackers escape the Gremlin query sandbox and obtain full read/write access to ANY database across customer tenants via a platform-wide key. Discovered by Wiz Research. 🔗 https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html #CVE #CloudSec #Azure #CyberSec
0
0
0
Cyber Security News @Cybersecuritynews@infosec.exchange · Jul 30, 2026
‼️Microsoft Teams, Entra ID, and Copilot all sit on Cosmos DB. A single flaw called CosmosEscape could have handed attackers the keys to all of them. Vulnerability Details: https://cybersecuritynews.com/cosmosescape-vulnerability/ #cybersecuritynews #Azure #Vulnerability
0
0
0
PSConfEU @psconf.eu@bsky.brid.gy · Jul 29, 2026

How do you explore your whole #Azure environment efficiently?

At #PSConfEU, @palmemanuel.bsky.social@bsky.brid.gy shows how Azure Resource Graph + VS Code enable: ✅ KQL queries at scale ✅ Better visibility ✅ Reusable insights

👉 youtu.be/xJ3OU7Rwq5k?si=ITE...

#PowerShell #automation #IT #DevOps #Conference

  • YouTube
0
0
0
OffSequence @offseq@infosec.exchange · Jul 25, 2026
CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: https://radar.offseq.com/threat/cve-2026-58630-cwe-284-improper-access-control-in-microsoft-azure-app-service-for-linux-12c1219307778a3e #OffSeq #Azure #Infosec #CVE2026_58630
0
0
0
OffSequence @offseq@infosec.exchange · Jul 25, 2026
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-kubernetes-c5571c5da7b404e3 #OffSeq #Azure #Kubernetes #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · Jul 25, 2026
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · Jul 24, 2026
CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: https://radar.offseq.com/threat/cve-2026-56160-cwe-285-improper-authorization-in-microsoft-azure-red-hat-openshift-aro-9a561de9f992bb49 #OffSeq #Azure #CVE202656160
0
0
0
Paco Hope @paco@infosec.exchange · Jul 24, 2026
Is that #azure outage still going on? I can't do shit* with #amtrak and I think that's part of it. I know they use MS for login, probably more than that. *: login on web, access reservation on mobile
0
1
0
OffSequence @offseq@infosec.exchange · Jul 24, 2026
CVE-2026-58275 | Microsoft Azure DNS (CRITICAL, CVSS 10): Missing authorization lets attackers escalate privileges remotely — integrity & availability at risk. Microsoft has patched server-side. Details: https://radar.offseq.com/threat/cve-2026-58275-cwe-862-missing-authorization-in-microsoft-azure-dns-8fa245e6deabe29a #OffSeq #Azure #CVE #CloudSecurity
0
0
0
USB Type-Steve :verified: @USBTypeSteve@infosec.exchange · Jul 23, 2026
*checks Microsoft Docs for correct syntax/example of an MgGraph set command* ofc it doesn't actually work in a real setting #msgraph #powershell #azure
1
0
0
Stanislav Zhelyazkov @StanZhelyazkov@infosec.exchange · Jul 22, 2026
This one https://developer.microsoft.com/en-us/changelog provides one RSS feed for for Azure, GitHub, and Microsoft developer updates. It solves one of my problems I had with Azure Updates RSS and Feedly. #Azure #GitHub #Microsoft
0
0
0
TrustedSec @trustedsec@bird.makeup · Jul 14, 2026
Azure container services are everywhere. Their attack surface? Often overlooked. Part 1 of this #blog series, @offsecpierogi@bird.makeup walks through offensive techniques targeting registries, keys, and container instances in modern #Azure environments. Read it now! https://hubs.la/Q04ptMB-0
430
0
16