LiteLLM supply-chain attack exposed credentials from 2,500 organizations including Microsoft and Amazon
What happened A supply-chain attack on LiteLLM, an open source tool for managing AI API calls, exposed terabytes of credentials from roughly 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock disclosed the breach, which compromised approximately 434,000 CI/CD pipelines during a 40-minute attack window in March 2026. The […]
Dragon Copilot physician apps hit Microsoft Marketplace, streamlining healthcare AI procurement
What launched Microsoft made Dragon Copilot Physician Apps and Agents available through Microsoft Marketplace, giving US-based healthcare organizations a new way to discover, evaluate, and purchase AI-powered clinical workflow tools. The move eliminates the need for separate vendor onboarding and consolidates billing through Microsoft’s existing marketplace infrastructure. Dragon Copilot is Microsoft’s AI assistant for clinical […]
Azure VMware Solution license-included service gets retirement date as Broadcom licensing shift bites
What changed Microsoft confirmed the Azure VMware Solution (AVS) license-included service will retire on August 30, 2027. The decision follows Broadcom’s VMware Cloud Foundation (VCF) licensing policy changes, which now require customers to bring their own portable licenses across all hyperscaler platforms. For AVS customers on license-included SKUs, this means a mandatory transition to bring-your-own-license […]
[Launched] Generally Available: Microsoft Defender security assessments for Azure Database for PostgreSQL Flexible Server
Microsoft Defender Security Assessments for Azure Database for PostgreSQL Flexible Server: Enhanced CSPM Coverage Microsoft Defender Cloud Security Posture Management (CSPM) has reached generally available status for Azure PostgreSQL Flexible Server databases, bringing comprehensive security assessment capabilities to this managed database service. This GA release marks a significant expansion of Microsoft’s cloud security posture management […]
[In preview] Public Preview: Azure SQL as a knowledge source in Foundry IQ
Azure SQL as a Knowledge Source in Foundry IQ: New Capabilities for AI Applications Microsoft Foundry (formerly Azure ML) has added Azure SQL Database as a first-class knowledge source in Azure AI Search, available in public preview. This development enables enterprise developers and solution architects building Copilot, RAG, and agentic experiences to expose authoritative table […]
[In preview] Public Preview: Agent mode for GitHub Copilot in SQL Server Management Studio (SSMS)
What Is GitHub Copilot Agent Mode in SSMS? GitHub Copilot Agent Mode brings autonomous, multi-step database operations directly into SQL Server Management Studio (SSMS). Announced in public preview in June 2026, this feature lets you describe a high-level goal in natural language — such as investigating a performance spike, analyzing a stored procedure, or finding […]
SafePal Data Breach Exposed Customer Records, But Not the Keys That Matter
SafePal, the cryptocurrency hardware wallet provider, confirmed a data breach that exposed personally identifiable information for roughly 39,798 customers. The good news, and it is genuinely reassuring: wallet seed phrases, private keys, passwords, and financial account data were not part of what leaked. The company states no evidence exists that the incident compromised access to […]
Protobuf Finally Has a Production-Grade LSP Server, and It Ships in the Buf CLI
Protocol Buffers just got the editor experience it always deserved. Buf has shipped a production-grade Language Server Protocol (LSP) server for Protobuf, built directly into the Buf CLI. That means go to definition, code completion, semantic syntax highlighting, and real-time diagnostics for .proto files, the kind of tooling that most languages have taken for granted […]
Qwen 3.8 27B Delivers Frontier Work on a Single GPU, If You Control Its Default Reasoning
Alibaba’s Qwen 3.8 27B is the latest open-weights flagship, and early impressions are strong: it is a 27B parameter, vision-capable model that hands a genuinely professional level of coding, tool-calling, and long-context work to a single consumer GPU. But it arrives with a catch that changes how you should use it. The default reasoning setting […]
Akira’s Safe Mode trick: why rebooting knocked out EDR
An Akira affiliate rebooted a Windows box into Safe Mode to disable EDR, exfiltrated data, then failed to encrypt. Here is what happened and what to monitor.
SAP Commerce Cloud CVE-2026-58231: a 10.0 RCE already under attack
SAP’s max-severity Commerce Cloud RCE, CVE-2026-58231, is being exploited within days of the patch. What it is and what to do now.
Evooo1Bot turns routers into SOCKS5 relays: what defenders should fix
A Mirai-derived botnet is turning residential and edge routers into SOCKS5 relays for criminal traffic, and quietly harvesting credentials along the way.