On Microsoft’s Lousy Cloud Security
2026-04-09T19:23:43Z•76b3cc93eeef7e6f8d60dd0969c1a58ab092134fe0d6b519ae234fc053defe01
.pthcloud-securitycorunaencryption-compulsionend-to-end-encryptionexploit-kitfcchong-kongiosmalicious-wheelmicrosoftpost-quantum-cryptographyprivacypypipythonrouter-securitysbomsigstoreslsasoftware-supply-chainstate-sponsoredsupply-chain-compromisewebinartvzero-dayzoom-recording
What happened
Collection of security commentary and news: a U.S. government evaluation reportedly found Microsoft’s cloud offering poorly documented and hard to assess; a PyPI supply-chain compromise (litellm v1.82.8) distributed a malicious .pth wheel that executes on Python startup; Google announces a timeline to migrate to post‑quantum cryptography by 2029; an advanced iPhone exploit kit dubbed “Coruna” (23 iOS vulnerabilities) was disclosed and appears state‑grade; Hong Kong changed rules permitting police to compel decryption/passwords; a New Mexico ruling raises legal pressure on end‑to‑end encryption
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- schneier_blog
- Record identifier
- 76b3cc93eeef7e6f8d60dd0969c1a58ab092134fe0d6b519ae234fc053defe01
- Enrichment time
- 2026-04-09T19:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.