Microsoft reported a critical vulnerability (CVE-2025-21415) in Azure AI Face Service that allowed attackers to bypass authentication via spoofing, leading to privilege escalation. The issue, classified as critical with a CVSS score of 9.9, has been fully mitigated, requiring no customer action. Microsoft emphasizes its commitment to transparency and encourages users to adopt security best practices.
Hackers Using HTTP Client Tools To Takeover Microsoft 365 Accounts
Hackers are increasingly using HTTP client tools to execute account takeover attacks on Microsoft 365, targeting 78% of tenants. Notable clients like OkHttp, Axios, and