logo

Hybrid clouds have two attack surfaces and you’re not paying enough attention to either

ID: d5e28894-c795-57a3-9569-5070757ad8b8

STIX ID: report--d5e28894-c795-57a3-9569-5070757ad8b8

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2026-04-23

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Researchers at Cymulate disclosed and responsibly reported four CVEs in Microsoft's Windows Admin Center that allowed token forgery/reuse and leveraged an unprotected on‑prem directory, enabling potential takeover of managed VMs and attacks crossing between cloud and on‑prem environments; Microsoft patched the issues and there is no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.