Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Research - From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel

Isolation is not the same thing as security. Ron Ben Yizhak from SafeBreach Labs presented this research at Black Hat USA and DEF CON: when Microsoft shipped Python in Excel, the code didn't run on a machine. It ran in an isolated container in Azure. So he asked the obvious question. How isolated is it, really? An isolated environment still has an attack surface. It just moves. See how Ron: If your teams are evaluating cloud-executed code features, this one is worth the full read—the methodology matters as much as the findings.

Escalated Privileges in Azure Containers with Python in Excel

A math function in Excel became a path to root in Microsoft's cloud. SafeBreach Labs researcher Ron Ben Yizhak reverse-engineered the isolated Azure containers behind Microsoft's Python in Excel feature—and found the "isolated" part didn't fully hold. Cloud isolation claims are a trust boundary. Trust boundaries get tested. What he found: Both issues were responsibly disclosed to Microsoft and patched between March and June 2026, and the research debuted at DEF CON 34.

Your CFO Just Left You a Voice Note. It Wasn't Her.

A voice note from your CFO on WhatsApp. Her cadence, her urgency—and a reference to a confidential acquisition discussed in a real meeting last Tuesday. North Korea's Blue Noroff builds these backwards: compromise a junior employee's calendar or inbox first, then train a voice model on the stolen context. By the time anyone thinks to verify, the emergency transfer is already sitting in an offshore account.

Ep. 79 - BeaverTail and InvisibleFerret: The Malware That Rewrites Itself for Every Target

North Korea has stopped writing bad phishing emails. In Part 2 of our DPRK deep dive, Tova Dvorin and Adrian Culley break down how the Reconnaissance General Bureau and Bureau 121 weaponized AI in 2026: Blue Noroff cloning a CFO's voice to authorize emergency liquidity transfers, real-time face swaps passing DevOps job interviews, and Lazarus using LLMs to polymorph BeaverTail and InvisibleFerret for every single target.

Ep. 76 - A Tale of Two SOCs: Invisible in One Network, Caught in 10 Minutes in the Other

CISA's own red team ran two critical-infrastructure assessments at once — and got opposite results. Host Tova Dvorin and SafeBreach offensive security engineer Adrian Culley break down advisory AA26-237A: how an ESC1 certificate template flaw and a default machine account quota chained into full domain compromise, why one SOC isolated three infected workstations in 10 minutes while the other never noticed, and the cloud identity gaps both organizations shared.

How does the SafeBreach Helm and the Anvilogic Integration Work Together?

SafeBreach Helm and Anvilogic help security teams accelerate the path from exposure to detection. SafeBreach Helm brings three AI agents together behind a plain-English interface: Analysis Agent — Prioritizes exposures based on real-world risk Validation Agent — Proves which exposures are actually exploitable by running real attacks SecOps Agent — Turns validated gaps into actionable fixes and works with Anvilogic to close the detection gap.

How Do You Operationalize CTEM and Prove It's Working?

Having the right security platform is only part of the equation. Two organizations can have similar security stacks and still achieve very different outcomes depending on how they operationalize their Continuous Threat Exposure Management (CTEM) program. In this video, learn what separates reactive, ad hoc security validation from a mature CTEM program—including: See how a structured CTEM program can turn continuous security validation into measurable progress across your organization.

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.