Microsoft reported a critical vulnerability (CVE-2025-21415) in Azure AI Face Service that allowed attackers to bypass authentication via spoofing, leading to privilege escalation. The issue, classified as critical with a CVSS score of 9.9, has been fully mitigated, requiring no customer action. Microsoft emphasizes its commitment to transparency and encourages users to adopt security best practices.
Abandoned AWS S3 Buckets Can be Reused to Hijack Global Software Supply Chain
WatchTowr Labs has identified a security flaw in abandoned AWS S3 buckets that could allow attackers to hijack software supply chains, potentially leading to large-scale