Live
Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up·MSFT +2.1%Microsoft Flags libssh Double-Free in Azure Linux, But the Real Impact May Be Broader·NVDA +0.2%CVE-2025-38185: Azure Linux Vulnerability & Microsoft's Security Response·GOOGL +1.7%Patch Azure Linux for CVE-2025-40913 Immediately, Microsoft Says (But Check Everything Else)·AMZN +1.1%CVE-2025-5994: Azure Linux Supply Chain Vulnerability & Microsoft's Security Response·MSFT +2.1%Azure Linux Attestation: Microsoft's Security Advisory Explained·NVDA +0.2%CVE-2025-38108 & Microsoft's VEX Attestations: A New Era in Azure Linux Supply Chain Security·GOOGL +1.7%Microsoft Patches LuaJIT Flaw in Azure Linux, But What About Your Other Microsoft Products?·AMZN +1.1%Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up·MSFT +2.1%Microsoft Flags libssh Double-Free in Azure Linux, But the Real Impact May Be Broader·NVDA +0.2%CVE-2025-38185: Azure Linux Vulnerability & Microsoft's Security Response·GOOGL +1.7%Patch Azure Linux for CVE-2025-40913 Immediately, Microsoft Says (But Check Everything Else)·AMZN +1.1%CVE-2025-5994: Azure Linux Supply Chain Vulnerability & Microsoft's Security Response·MSFT +2.1%Azure Linux Attestation: Microsoft's Security Advisory Explained·NVDA +0.2%CVE-2025-38108 & Microsoft's VEX Attestations: A New Era in Azure Linux Supply Chain Security·GOOGL +1.7%Microsoft Patches LuaJIT Flaw in Azure Linux, But What About Your Other Microsoft Products?·AMZN +1.1%

Supply Chain Security

The latest Supply Chain Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:12 PM
Latest Most Read Breaking
Sort
Mbed Tls · Memory Safety

Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up

A bug in the widely used Mbed TLS encryption library fails to scrub decrypted plaintext from memory after certain read operations, potentially exposing session tokens, passwords, and other secrets to...

Advertisement
Azure Linux · Cve 2025 5994

CVE-2025-5994: Azure Linux Supply Chain Vulnerability & Microsoft's Security Response

The disclosure of CVE-2025-5994 has reignited critical conversations about supply chain security in cloud infrastructure, particularly concerning Microsoft's Azure Linux distribution and the broader...

SE Security Desk·21w ago
Azure Linux · Cve 2025 49812

Azure Linux Attestation: Microsoft's Security Advisory Explained

Microsoft's recent security advisory regarding Azure Linux and CVE-2025-49812 has sparked significant discussion in the IT security community, highlighting the nuanced relationship between...

SE Security Desk·21w ago
Azure Linux · Linux Kernel

CVE-2025-38108 & Microsoft's VEX Attestations: A New Era in Azure Linux Supply Chain Security

The recent disclosure of CVE-2025-38108, a race condition vulnerability in the Linux kernel's Random Early Detection (RED) queue management algorithm within the net_sched subsystem, has become far...

SE Security Desk·21w ago
Azure Linux · Luajit

Microsoft Patches LuaJIT Flaw in Azure Linux, But What About Your Other Microsoft Products?

Microsoft has shipped security updates for Azure Linux to address an out-of-bounds read vulnerability in the LuaJIT just-in-time compiler, but the company's public attestation stops at its own...

SE Security Desk·21w ago
Azure Linux · Cve 2025 32052

Azure Linux Confirmed Exposed to CVE-2025-32052, But Libsoup Vulnerability Could Lurk in More Microsoft Offerings

Microsoft has publicly confirmed that its Azure Linux distribution includes a vulnerable version of the libsoup library, putting virtual machines and container workloads running the cloud-optimized...

SE Security Desk·21w ago
Artifact Discovery · Azure Linux

Microsoft’s First CSAF/VEX Attestation Flags Azure Linux Deadlock Bug (CVE-2025-22014)—Here’s How to Check Your Entire Image Catalog

In October 2025, Microsoft disclosed that a newly identified Linux kernel vulnerability, tracked as CVE-2025-22014, affects its Azure Linux distribution. The advisory, published via Microsoft’s new...

SE Security Desk·21w ago
Ai Security · Data Protection

AI Transactions Surge 91% to 1 Trillion; 39% Blocked as Data Leak Fears Mount

In 2025, businesses worldwide sent nearly one trillion AI-related transactions through their networks—a 91% increase over the previous year—and security teams were forced to block 39% of that...

AI AI & Copilot Desk·21w ago
Cgo · Go Modules

Go Toolchain CVE-2023-29402: Critical Supply Chain Vulnerability Analysis

The Go programming language's toolchain, widely used by developers worldwide, was quietly exposed to a high-risk code-injection vulnerability in 2023 that continues to offer critical lessons for...

SE Security Desk·21w ago