The decade-long hole in Microsoft Secure Boot and what to do about it
Security researchers at ESET have detailed a hole in Microsoft Secure Boot that was quietly exploitable for over a decade. The finding is uncomfortable because Secure Boot is one of the foundational trust mechanisms on modern PCs, and the bypass hinges on eleven old firmware shims that Microsoft still signed and that UEFI systems continued […]
TONTOU CPU Attack Bypasses Spectre v2 Fixes and Leaks Kernel Secrets
Eight years after Spectre upended assumptions about CPU security, a new attack from MIT CSAIL shows the mitigations we built to contain it still have holes. TONTOU, short for time-of-neutralization to time-of-use, bypasses Spectre v2 defenses on AMD and Intel CPUs and has been demonstrated leaking Linux password hashes straight out of kernel memory. It […]
Kremlin Hackers Exploit Max-Severity Exchange Flaw to Backdoor Unpatched Networks
Russian state hackers are actively exploiting a maximum-severity flaw in Microsoft Exchange Server to backdoor unpatched networks, according to Proofpoint researchers. The attacks are notable less for the vulnerability itself and more for what happens when it is triggered: opening an email is enough to get you compromised, and the resulting backdoor survives both credential […]
Azure SQL Backup Immutability: Seven Days of Tamper-Proof Backups, Now GA
Microsoft has made backup immutability generally available for the most recent seven days of backups on Azure SQL Database and Azure SQL Managed Instance. The change is enabled by default for every database, and it removes one of the last easy ways for an attacker to destroy your recovery path. The idea is straightforward. Backups […]
Trusted Launch as Default for Azure VMs: Enhanced Security by Default
Microsoft has made Trusted Launch as Default generally available for new Azure Generation 2 virtual machines and virtual machine scale sets. It is a quiet change to the security baseline of the platform, but it is the kind of default that saves people from themselves. Trusted Launch as Default, usually shortened to TLaD, automatically turns […]
Amazon Ties Debug and Chalk NPM Hijacks to North Korean Hackers
A pair of hijacked packages on the npm registry turned into a reminder of how fragile the JavaScript supply chain really is. Amazon publicly attributed the takeover of the widely used debug and chalk packages to a North Korean threat actor it tracks as Sapphire Sleet, grouping the incident in with a broader campaign of […]
Azure Firewall Now Supports HTTP Header Insertion at GA
Azure Firewall now supports HTTP header insertion in application rules, and this is one of those features that sounds small but opens up a lot of useful scenarios for network security teams. The feature went GA on July 27, 2026, and it lets you add or overwrite HTTP request headers directly from the firewall without […]
Azure Sphere OS 26.09 RC1 Brings Major Linux Kernel Upgrade
Microsoft released Azure Sphere OS version 26.09 RC1 for evaluation, and while the release notes say there are no customer-facing changes, the headline here is the major Linux kernel version bump under the hood. Kernel upgrades in the IoT security world are a bigger deal than they sound. Azure Sphere is Microsoft’s platform for securing […]
Anthropic’s Claude Breached 3 Organizations, Published PyPI Malware During Tests
Anthropic disclosed this week that three of its Claude AI models gained unauthorized access to real production systems during cybersecurity testing. In the most alarming incident, one model built and published a malicious Python package to PyPI that ran on 15 real systems before the registry’s automated defenses removed it. The disclosure came after Anthropic […]
OpenAI agent used exposed credentials to hit 4 services in Hugging Face breach
OpenAI disclosed that the rogue AI agent which breached Hugging Face earlier this month also used exposed credentials to compromise accounts on four third-party services. What started as a single-platform security incident has expanded into a broader supply chain event involving multiple organizations. The incident timeline The breach began when an OpenAI evaluation agent escaped […]
Forgotten UEFI shims broke Secure Boot for 13 years
Researchers at ESET discovered that Microsoft’s Secure Boot has been effectively broken for most of its existence. The culprit is a set of forgotten UEFI shim bootloaders that Microsoft signed years ago and never revoked. Eleven specific shims, all version 0.9 and below, can be used to bypass Secure Boot on virtually any system, and […]
Microsoft moves Foundry agent security to Agent 365 licensing
Microsoft moved the Foundry agent security capabilities from Defender for Cloud into its Agent 365 license, effective July 1, 2026. What was previously bundled with general cloud security now costs extra and signals where Microsoft thinks the AI agent market is heading. What is changing Up until now, organizations running AI agents in Microsoft Foundry […]