SPONSORED FEATURE: Your M365 and Azure data might not be as safe as you think from ransomware; time for a reality check

Organizations relying on Microsoft's cloud services, including Microsoft 365, Azure, and Entra ID, often operate under a significant misconception regarding data protection and recovery in the event of a cyberattack. While Microsoft ensures the availability and operational continuity of its services, it does not provide comprehensive data backup and recovery solutions that protect against ransomware or other forms of data loss originating from customer-side compromises. This distinction is crucial and is governed by a shared responsibility model, where customers are ultimately accountable for their data, devices, accounts, and identities within Microsoft's cloud ecosystem.
The gap between service availability and true cyber recovery has widened due to several factors. Modern cyberattacks increasingly target human weaknesses and identity-based initial access, rather than exploiting technical vulnerabilities. Attackers leverage AI-powered tools for sophisticated phishing, social engineering, and credential stuffing, often exploiting password reuse. Microsoft Entra ID, the cloud-based identity and access management service, has become a primary target. Once compromised with stolen credentials, attackers can gain unfettered access to data across mailboxes, OneDrive, SharePoint, and Teams, enabling them to launch ransomware attacks at leisure without triggering immediate alarms.
Another contributing factor is the widespread adoption of Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) models. Many organizations distribute their workloads across on-premises, SaaS, and cloud environments but often fail to apply consistent levels of data protection and management across all these locations. This creates vulnerabilities where data might be backed up in various places, but its recoverability in a breach is not uniformly assured. The "as a service" model, while popular, can become a weak link when ransomware strikes.
Furthermore, the proliferation of compliance requirements mandating robust cyber resilience, including specific backup and recovery procedures, adds pressure on organizations that are often ill-prepared. These combined pressures create a window of opportunity for criminals to inflict substantial harm to data, business operations, and compliance standing between the time of an attack and the restoration of SaaS availability. Microsoft's native retention and recovery capabilities are primarily designed for short-term issues like accidental deletion and certain aspects of data governance, not for comprehensive cyber resilience against sophisticated attacks.
To address this critical gap, experts recommend implementing independent backup protection. This involves maintaining a copy of an organization's data in an environment separate from its primary operational platform. Such a solution should be immutable, allowing for recovery even if the Microsoft ecosystem itself is compromised or unavailable. Dedicated cloud-to-cloud backup solutions, stored offsite in a third-party datacenter, are increasingly becoming a requirement for cyber insurance and compliance. By pulling copies of frequently targeted data from the Microsoft tenant and storing them externally, critical assets remain secure even if SaaS credentials are stolen.
In the event of a compromise, this approach allows for the restoration of data directly back into the SaaS environment, even if the original tenant has been destroyed. Some organizations find it more efficient to establish a new tenant and rebuild from an independent backup than to attempt to regain access to a compromised one. Effective solutions should prioritize ease of use and deployment, ensuring reliable recovery without extensive human intervention. They should also integrate the restoration of Microsoft 365 and Entra ID into a single workflow, ensuring that identity and the data it protects are brought back online in the correct sequence.
For example, Datto, a cybersecurity and data protection company, offers solutions like Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID. These products are designed to bridge the recovery gap by storing protected copies of tenant data in the Datto Cloud, separate from the Microsoft environment, thereby preventing a compromised production tenant from affecting the recovery point. Such platforms aim to provide a trusted and straightforward recovery process, protecting millions of users globally. Organizations must recognize that a ransomware attack is a matter of "when," not "if," making robust recovery planning essential.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed