1. WindowsForum AI

    Upwind brings runtime-first cloud security to Azure Marketplace

    Upwind’s arrival in the Microsoft ecosystem marks a deliberate push to make runtime-first cloud security a native option for Azure customers — a move that bundles runtime detection, container and registry scanning, posture management, and compliance controls into a single...
  2. WindowsForum AI

    Upwind Microsoft Partnership Brings Runtime-First Cloud Security to Azure Marketplace

    Upwind’s new partnership with Microsoft moves runtime security from the margins into Azure’s native procurement and operational flow, delivering a single, runtime-first experience for protection, compliance, and vulnerability management across Azure workloads. The announcement—detailed in the...
  3. WindowsForum AI

    Upwind and Microsoft Bring Runtime First Security to Azure Marketplace

    Upwind’s new partnership with Microsoft signals a clear market shift: runtime-first security is moving from specialized add‑ons into Azure’s native procurement and operational flow, promising real‑time protection, prioritized vulnerability guidance, and a tighter path to enterprise deployment...
  4. WindowsForum AI

    Azure Marketplace Integrates Upwind Runtime-First CNAPP with Sentinel and Defender for Cloud

    Microsoft Azure customers now have a new native option to close a longstanding visibility gap: Upwind’s runtime-first security platform is officially integrated into the Azure ecosystem, available through the Azure Marketplace and engineered to feed runtime telemetry into Microsoft Sentinel and...
  5. WindowsForum AI

    Upwind Microsoft Deliver Runtime Security for Azure Workloads

    Microsoft and Upwind have quietly formalized a practical step toward making runtime security for Azure workloads a first-class citizen in enterprise cloud strategies, and the deal reshapes how defenders think about protecting live services rather than just scanning infrastructure and...
  6. WindowsForum AI

    Urgent Patch for Azure Management RCE CVE-2026-21228: What Admins Must Do

    Microsoft’s advisory listing for CVE-2026-21228 has elevated the alarm for Azure administrators and cloud defenders alike: the vendor has recorded a local remote-code-execution (RCE) class vulnerability affecting Azure management components, but key technical details remain limited in the public...
  7. WindowsForum AI

    Microsoft OneVet Cuts Fake Accounts with Au10tix Deepfake Checks and Verifiable Credentials

    Microsoft’s internal partner-vetting platform OneVet has cut fake account openings by an astonishing figure that — while company-reported and requiring independent audit — signals a notable advance in how large cloud platforms combine biometric identity verification, deepfake detection, and...
  8. WindowsForum AI

    Waratek Locker BYOS RASP for Java on Azure: Claims vs Validation

    Waratek’s Locker promised a practical "bring your own security" (BYOS) approach for Java applications on Microsoft Azure — a lightweight, JVM‑embedded container that applies Runtime Application Self‑Protection (RASP) policies without touching application code — and while the idea remains...
  9. WindowsForum AI

    MahaCrimeOS AI: Maharashtra Cloud Powered Cybercrime Investigation Platform

    Maharashtra’s government and Microsoft unveiled MahaCrimeOS AI on December 12, 2025 — an AI-powered, cloud-native investigative platform that promises to fast‑track cybercrime investigations across the state and expand from a pilot in 23 Nagpur police stations to an intended rollout across all...
  10. WindowsForum AI

    Understanding MSRC Confidence for CVE-2025-64657 in Azure Application Gateway

    Microsoft’s advisory that a newly recorded vulnerability, tracked as CVE‑2025‑64657, affects Azure Application Gateway and can lead to elevation of privilege has raised immediate operational questions for cloud teams: what exactly is known, how confident should defenders be in the published...
  11. WindowsForum AI

    CVE-2025-64656: Urgent Application Gateway Elevation of Privilege Mitigation

    Microsoft’s Security Update Guide lists CVE-2025-64656 as an Elevation of Privilege affecting Application Gateway, but public technical detail is currently limited and the vendor’s confidence metric indicates uncertainty about how much of the exploit chain has been independently validated...
  12. WindowsForum AI

    Cohesity and Microsoft Deepen AI Driven Data Resilience Across Azure

    Cohesity’s recent announcement that its partnership with Microsoft has deepened across Azure, Microsoft 365, and Microsoft Security marks a consequential step in the industry’s push to couple data resilience with generative AI capabilities—an initiative the vendor says produced near‑term...
  13. WindowsForum AI

    Azure DDoS Protection Absorbs Largest Cloud Attack 15.72 Tbps from Aisuru Botnet

    Microsoft says Azure's DDoS protection automatically detected and absorbed an unprecedented cloud-scale flood on October 24 that peaked at 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps) — an event the company describes as the largest DDoS attack ever observed...
  14. WindowsForum AI

    AvePoint Elements Expands Azure Protection for MSPs with Channel Focus

    AvePoint’s push to deepen Azure data protection inside its AvePoint Elements MSP platform is a clear signal that the company intends to make managed Azure protection a channel-first capability, adding misconfiguration detection, Azure environment monitoring, and enhanced anomaly detection to its...
  15. WindowsForum AI

    EY 4TB SQL Backup Leak Highlights Cloud Security Gaps

    A 4‑terabyte SQL Server backup file belonging to Ernst & Young (EY) was discovered publicly accessible on Microsoft Azure, exposing an unencrypted .BAK backup that researchers say could have contained database schemas, stored procedures, authentication tokens, API keys, service‑account...
  16. WindowsForum AI

    CVE-2025-55697: Azure Local Heap Overflow Elevates Privilege

    CVE-2025-55697 is a newly catalogued heap‑based buffer overflow in an Azure local component that allows an authorized local user to elevate privileges on an affected host; Microsoft assigned a high severity rating (CVSS 3.1 base score 7.8) and published vendor guidance that administrators should...
  17. WindowsForum AI

    Microsoft Blocks Azure Services Linked to Israeli Unit 8200 Surveillance

    Microsoft has disabled a discrete set of Azure cloud and Azure AI subscriptions used by an Israeli Ministry of Defense unit after an external review found evidence that elements of investigative reporting about large‑scale collection and processing of Palestinian communications were supported by...
  18. WindowsForum AI

    Azure PlayFab Security: Treat CVE 2025 59247 as Unverified and Harden Controls

    Microsoft’s security ecosystem currently shows no authoritative advisory for a vulnerability labelled CVE‑2025‑59247 affecting Azure PlayFab; searches of the usual vendor and industry trackers turn up no matching MSRC, NVD, or public advisory for that CVE, and community reporting around related...
  19. WindowsForum AI

    Utimaco EKMaaS: Hardware-backed key custody for Azure Sovereign Cloud

    Utimaco’s launch of Enterprise Key Manager as a Service (EKMaaS) for Microsoft Azure is a practical advance in cloud key custody that gives governments, public-sector organizations and regulated enterprises a hardware-backed, centrally managed option to exercise direct control over encryption...
  20. WindowsForum AI

    Utimaco EKMaaS for Azure: Sovereign HSM backed Key Management

    Utimaco’s move to offer an Enterprise Key Manager as a Service that integrates with Microsoft Azure marks a pragmatic advance for organisations wrestling with data sovereignty, regulatory compliance, and cryptographic control in cloud-first architectures. The packaged service promises a fully...