DHS urges Microsoft customers to update Azure to avoid security flaw

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency is urging Microsoft cloud customers to reset their security keys in light of a recent vulnerability that may have exposed customer data. The flaw, discovered by researchers at Wiz, would have allowed any customer using Microsoft’s Azure Cosmos database to read, write and delete another user’s information without authorization. Cosmos DB is used by thousands of organizations, including Coca-Cola, Exxon Mobil and a number of other Fortune 500 companies. “Although the misconfiguration appears to have been fixed within the Azure cloud, CISA strongly encourages Azure Cosmos DB customers to roll and regenerate their certificate keys and to review Microsoft’s guidance on how to secure access to data in Azure Cosmos DB,” CISA wrote in an alert Friday. Microsoft reported in a blog Friday that it contacted customers who had the Azur Cosmos feature that contained the vulnerability activated during the […]

The post DHS urges Microsoft customers to update Azure to avoid security flaw appeared first on CyberScoop.

Continue reading DHS urges Microsoft customers to update Azure to avoid security flaw

Microsoft Azure vulnerability exposed thousands of cloud databases

Microsoft is warning customers of its Azure cloud platform about a software vulnerability that exposed data belonging to thousands of clients for roughly two years. The flaw would have allowed any Azure Cosmos DB user to read, write and delete another customer’s information without authorization, researchers found. Cosmos DB is used by thousands of organizations, including Coca Cola, Exxon Mobil and a number of other Fortune 500 companies. Microsoft has since resolved the issue, the company said. “We fixed this issue immediately to keep our customers safe and protected,” a Microsoft spokesperson told CyberScoop. There was no evidence that hackers or any other outsider exploited the vulnerability to access customer data, according to the company. Reuters first reported on the vulnerability, which was discovered by Wiz research team. Microsoft fixed the vulnerability within 48 hours of its disclosure on August 12, but that the vulnerability had been exploitable since mid-2019, […]

The post Microsoft Azure vulnerability exposed thousands of cloud databases appeared first on CyberScoop.

Continue reading Microsoft Azure vulnerability exposed thousands of cloud databases

Approov Alliance and Integration Program offers security solutions to protect APIs

Approov introduced the Approov Alliance and Integration Program to ensure that the critical elements of comprehensive mobile app API protection are rigorously tested and work together harmoniously and seamlessly to avoid both data leakage and exposure … Continue reading Approov Alliance and Integration Program offers security solutions to protect APIs

Abnormal Security joins MISA to help customers combat global cybersecurity threats

Abnormal Security announced it has joined the Microsoft Intelligent Security Association (MISA). Abnormal was nominated for membership based on how its platform uses Microsoft Azure Active Directory APIs (SIGNIN, ALERT, USER, GROUP, DIRECTORYOBJECT, RI… Continue reading Abnormal Security joins MISA to help customers combat global cybersecurity threats

ACI Worldwide reveals that its Fraud Management solution protects more than one billion consumers

ACI Worldwide announced that it protects more than one billion consumers globally from new and emerging threats in the era of real-time payments and open banking through its ACI Fraud Management solution. While the pandemic has accelerated the global s… Continue reading ACI Worldwide reveals that its Fraud Management solution protects more than one billion consumers

Quest Software RMAD DRE 10.2 offers Secure Storage solution to protect AD backups from malware

Quest Software announced innovation in the latest release of Recovery Manager for Active Directory Disaster Recovery Edition that will help organizations eliminate the risk of malware re-infection throughout the Active Directory recovery process to min… Continue reading Quest Software RMAD DRE 10.2 offers Secure Storage solution to protect AD backups from malware

Baffle raises $20M to secure cloud data

Baffle announced that it has raised $20 million in Series B funding led by new investor Celesta Capital, with contributions from National Grid Partners, Lytical Ventures and Nepenthe Capital, and follow-on investments from True Ventures, Greenspring As… Continue reading Baffle raises $20M to secure cloud data

Orca Security Partner Program helps partners create greater customer value and boost growth

Orca Security announced a robust global partner program to further extend the reach of its SaaS-based platform for workload and data protection, cloud security posture management, and vulnerability management to enable customers across all markets to s… Continue reading Orca Security Partner Program helps partners create greater customer value and boost growth

PacketFabric Cloud Router site-to-site VPN support expands enterprise cloud networking options

PacketFabric announced that it has released native support of IPsec VPN tunnels as a connection type for its Cloud Router product. In addition, Cloud Router now supports Network Address Translation (NAT), allowing enterprises to build premium private c… Continue reading PacketFabric Cloud Router site-to-site VPN support expands enterprise cloud networking options

OwnBackup raises $240M to expand its backup and recovery solutions across other cloud platforms

OwnBackup announced a Series E investment of $240 million co-led by Alkeon Capital and B Capital Group, including a secondary investment in the company by BlackRock Private Equity Partners and Tiger Global. Existing investors Insight Partners, Salesfor… Continue reading OwnBackup raises $240M to expand its backup and recovery solutions across other cloud platforms