Cloud Security
The latest Cloud Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Hot Chips 2025: Microsoft Unveils Azure Integrated HSM and Open-Source Caliptra 2.0 Root of Trust
At Hot Chips 2025, Microsoft pulled back the curtain on a fundamental redesign of Azure’s hardware security, revealing a custom security ASIC called Azure Integrated HSM and an open-source silicon...
Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook
Organizations relying on Microsoft Copilot's agent policies to restrict AI access are confronting a stark reality: the controls have been breaking silently. In recent weeks, multiple independent...
How Metadata-Driven Zero Trust on Azure Reinforces AI Pipelines Against Modern Attacks
Microsoft’s Azure platform now offers a battle-tested blueprint for locking down machine learning operations using a metadata-driven zero-trust architecture—one that InfoWorld contributor Vikram...
Critical Copilot Audit Flaw Fixed Silently as Governance Issues Mount
Microsoft has patched a critical flaw in Microsoft 365 Copilot that allowed attackers to access and summarize enterprise files without leaving any trace in audit logs—and did so without notifying...
Microsoft Copilot’s ‘No Link’ Prompt Trick Caused Monthslong Audit Log Gaps, No Customer Warning
Microsoft 365 Copilot silently suppressed document access records for months whenever users asked it to summarize a file without including a source link, leaving security teams with empty audit...
Microsoft's Enterprise AI Blueprint: Copilot Everywhere, Custom Silicon, and the Battle for Trust
Microsoft’s AI platform has evolved from a research-driven experiment into a full-fledged enterprise strategy that embeds generative intelligence across every layer of its stack. The Redmond giant...
Microsoft Silently Patches Copilot Audit Blind Spot That Allowed Silent Data Exfiltration
Microsoft quietly fixed a critical gap in Microsoft 365 Copilot’s audit logging in mid‑August 2025 after researchers proved that a simple prompt tweak could make the AI assistant summarize...
Zscaler CEO's 'Wonderful AI' Remarks Ignite Customer Log Training Controversy—Company Denies Using Private Data
Zscaler CEO Jay Chaudhry set off a firestorm when he boasted that the company harnesses over half a trillion daily transactions—including full URLs and proprietary logs—to train its AI models,...
CVE-2025-53763: Microsoft Flags Azure Databricks Privilege Escalation Flaw, Urges Immediate Defensive Actions
Microsoft has disclosed a new privilege escalation vulnerability in Azure Databricks, tracked as CVE-2025-53763, which could allow an attacker with network access to elevate their privileges within...
18 Arrested as Microsoft Staff Protest Azure’s Role in Israeli Surveillance, Triggering External Audit
Eighteen people were arrested at Microsoft’s Redmond, Washington headquarters on August 20, 2025, after demonstrators—including current and former employees—splashed red paint across campus...
Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces
A security researcher discovered that a simple prompt technique could make Microsoft 365 Copilot summarize sensitive corporate files without leaving the required Purview audit records. Microsoft...
18 Microsoft Employees Arrested in Protest Over Azure's Deepening Role in Gaza Conflict
A small but highly visible standoff at Microsoft’s Redmond campus this week crystallized a wider crisis for the company: employees confronting management over allegations that Microsoft’s cloud...