Microsoft

Orca Security takes Azure Synapse off its naughty list after six-month investigation.

Microsoft warned that a malicious campaign targeting SQL Servers is using an "uncommon living-off-the-land binary" that to achieve persistence on compromised systems -- saying that defenders need to pay increased attention to abuse of the sqlps.exe which ships with SQL Server as standard. Without naming the attackers

"This is a major attack surface and not consistent with the level of security that public cloud customers expect."

Attackers continue to accelerate their weaponisation of newly-discovered flaws, the Five Eyes list of most-exploited vulnerabilities of 2021 shows. Contrary to some reports suggesting fears of mass-exploitation had been over-indexed, the flaw in Log4j joined the most widely-exploited vulnerabilities last year, despite only being discovered at the year's