#AzureSecurity

2025-11-23

New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
Read the blog 👉 marshsecurity.org/sentinel-sat

In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.

Most teams aren’t getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.

- Auto-create tasks when automation fails (so nothing slips through the cracks)
- Auto-complete tasks when automation succeeds
- Use tasks to verify automation outcomes
- Build engineering feedback loops and automation #QA

Read the blog 👉 marshsecurity.org/sentinel-sat

#MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
#CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
#CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations

Offensive Sequenceoffseq@infosec.exchange
2025-10-30

🛡️ CVE-2025-12479 (CRITICAL, CVSS 10): Azure Access BLU-IC2/IC4 (≤1.19.5) lack CSRF tokens, allowing full remote compromise—no patch yet. Apply WAFs, enforce header checks, and restrict access. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CSRF #AzureSecurity

Critical threat: CVE-2025-12479: CWE-352 Cross-Site Request Forgery (CSRF) in Azure Access Technology BLU-IC2
Offensive Sequenceoffseq@infosec.exchange
2025-10-29

🚨 CRITICAL: CVE-2025-12423 (CVSS 10) in Azure BLU-IC2 & IC4 (≤1.19.5) allows remote DoS via protocol manipulation (CWE-248). No patch yet—apply filtering, segment networks, and monitor logs. Stay proactive! radar.offseq.com/threat/cve-20 #OffSeq #AzureSecurity #CVE2025 #BlueTeam

Critical threat: CVE-2025-12423: CWE-248 Uncaught Exception in Azure Access Technology BLU-IC2
Offensive Sequenceoffseq@infosec.exchange
2025-10-29

🔴 CVE-2025-12424 (CRITICAL): Azure Access BLU-IC2 & BLU-IC4 (≤1.19.5) affected by SUID-bit privilege escalation flaw. No patch yet — restrict & monitor SUID binaries now to prevent full compromise. Details: radar.offseq.com/threat/cve-20 #OffSeq #AzureSecurity #CVE #UnixSec

Critical threat: CVE-2025-12424: CWE-269 Improper Privilege Management in Azure Access Technology BLU-IC2
2025-05-20

I wrote a brief Playbook, how to get started with securing the Azure AI Service's in your environment. Azure AI services provides multiple layers of security that you should consider when implementing a solution, which I present in this blog post:

vasenius.fi/example-playbook-t

#AISecurity #AzureAIServices #AzureSecurity

2025-04-22

A seemingly harmless Chrome extension can now hijack your digital keys—stealing Azure session cookies and bypassing MFA. Curious how this stealthy Cookie-Bite attack works and what you can do to stay secure?

thedefendopsdiaries.com/unders

#cookiebiteattack
#azuresecurity
#sessioncookies
#cyberthreats
#microsoft365security

Lenin alevski 🕵️💻alevsk@infosec.exchange
2025-03-25

New Open-Source Tool Spotlight 🚨🚨🚨

Blacksmith is a cloud-native adversary simulation tool that scales offensive testing in Azure. It’s built to automate simulation setups, leveraging Azure services like Sentinel for detection validation. Useful for red teaming and continuous security improvement.

#ThreatHunting #AzureSecurity

🔗 Project link on #GitHub 👉 github.com/OTRF/Blacksmith

#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity

— ✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️

Samarasam Sadasivamsamarasam@fosstodon.org
2025-01-09

As part of AZ-500 learning, I explored Container Registry and Azure Kubernetes Service and shared the step by step instructions on how to implement these in Azure.
Read the blog here and let me know your thoughts:

medium.com/@samarasams/deployi

#CloudSecurity #Azure #AzureKubernetes #AzureSecurity #Containers #Docker #kubernetes

2024-12-31

Azure Blunder: Microsoft’s Airflow Integration Opens Door to Cyber Mischief!

Discover the low-severity flaws in Azure Data Factory that could let attackers play secret admin. Are your Kubernetes clusters safe? #AzureSecurity
thenimblenerd.com/?p=1033097

2024-11-23

Does anybody have experience with Cloudbreach.io’s Breaching Azure training? Is it worth the investment? #BreachingAzure #Cloudbreach #OffensiveAzureSecurity #AzureSecurity

2024-10-15

Looks like #Microsoft forgot to register the domains listed in their SDK, which has now been taken over

xcancel.com/watchtowrcyber/sta

#azure #cloudsecurity #AzureSecurity #cloudfail

2024-08-20

Azure Kubernetes Clusters Vulnerable To Sneaky TLS Bootstrap Attack
Today, we're diving into the world of cybersecurity and exposing a sneaky attack that has been targeting Azure Kubernetes Clusters. That's right, your beloved cloud platform may not be as secure as you think!

cloudhosting.evostrix.eu/azure

2024-07-11

Are your Azure Storage Accounts locked down to a network? Are you still resisting Private Endpoints? Keep your data secure #AzureSecurity #ConfigurationMonitoring #MicrosoftSentinel

2024-06-25

Stay informed about potential security vulnerabilities in your Azure services by subscribing to Defender for Cloud's security alerts and recommendations. #SecurityAlerts #AzureSecurity

2024-06-11

Safeguard your Azure environment by leveraging Microsoft Sentinel's AI-driven analytics to detect and respond to security threats in real-time. #AzureSecurity #MicrosoftSentinel

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst