LIVE · cybersecurity feed
Live wire
aimedium

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

Microsoft has developed an internal AI system to proactively evaluate and strengthen its cloud infrastructure. This system operates at AI speed to match the scale and complexity of Microsoft's hyper-scale environments, ensuring security controls are robust and effective. While not a customer-facing product, the insights gained will inform future product improvements.

zeroday.news · 24d ago

Microsoft has developed an internal artificial intelligence system designed to proactively assess and enhance the security of its cloud infrastructure. This AI-driven approach operates at a speed commensurate with the vast scale and intricate nature of Microsoft's hyper-scale cloud environments.

The system's primary function is to continuously evaluate and strengthen the security controls in place. By leveraging AI, Microsoft aims to identify potential vulnerabilities and ensure the robustness and effectiveness of its security measures in real-time.

This internal initiative is not intended as a product for customers. Instead, the knowledge and insights generated by the AI system will be utilized to inform and guide the development of future security features and improvements within Microsoft's cloud offerings.

The rapid pace of cloud operations necessitates advanced security solutions capable of keeping up with the dynamic nature of these environments. The AI system is built to address this challenge, enabling proactive rather than reactive security measures.

By operating at "AI speed," the system can analyze large volumes of data and complex interactions within the cloud infrastructure, identifying potential risks that might be missed by traditional security methods. This allows for a more agile and comprehensive security posture.

The proactive evaluation process aims to ensure that security controls remain effective against evolving threats. This continuous assessment is crucial for maintaining the integrity and safety of a hyper-scale cloud platform.

While specific details about the AI system's architecture or the types of security controls it evaluates are not publicly disclosed, the overarching goal is to enhance the inherent security of Microsoft's cloud services.

The insights derived from this internal project are expected to contribute to a more secure cloud ecosystem for all users, as they will be integrated into the ongoing evolution of Microsoft's product security.

aicloud securitymicrosoftvulnerability management
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.