『Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers』のカバーアート

Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

Cloudy with a Chance of Insights | A Microsoft Cloud (Azure, M365) Show for Architects & Engineers

著者: Richard Hogan David Rowley and Cyrus Irandoust
無料で聴く

Cloudy with a Chance of Insights is a practitioner‑led podcast for architects, engineers, and security professionals working with the Microsoft Cloud. In each episode, we take a grounded, experience‑led look at Azure, M365, Copilot, Security, and AI, focusing less on release notes and more on what actually changes in real environments. We discuss what breaks, what gets harder, what’s worth paying attention to, and what can usually wait. Expect opinionated conversation, technical context, and the occasional bit of healthy scepticism rather than marketing hype or surface‑level news summaries.Richard Hogan, David Rowley and Cyrus Irandoust 政治・政府
エピソード
  • Passkeys, PLCs, and America's New Cyber Privateers
    2026/08/24

    David opens with a question that runs through the whole episode: does removing operational complexity solve the problem, or just relocate who is responsible for it. Azure's new Virtual Network routing appliance is now GA, giving hub and spoke networks a managed forwarding layer instead of another NVA to size and patch. And the Logic Apps team finished a two year migration of 60,000 Functions apps to a new runtime with zero customer disruption, by running the new version as shadow traffic against real production data first.

    Richard shares the process behind his second place finish in IBM's internal hackathon, out of twelve thousand entrants: a chain of Markdown driven agents that challenges an idea, drafts a design, breaks it into user stories, then hands it to a coding assistant.

    David also covers two security stories. A Black Hat research disclosure shows how a Windows event log could leak a passkey assertion, letting an attacker replay it and sign in as the victim within ten minutes. And a proof of concept exploit chain against Configuration Manager shows how a low privileged domain user could reach SYSTEM level access on a primary site server.

    Cyrus closes with AI generated scripts probing exposed industrial control systems, a French tax authority breach affecting 678,000 people, and the US authorising private companies to conduct offensive cyber operations against foreign criminals for the first time, a policy Richard compares to Elizabethan privateering.

    Links
    • Azure Virtual Network routing appliance GA
    • The Logic Apps migration writeup
    • Pass the passkey research
    • Configuration Manager exploit chain
    • CISA advisory on PLC attacks
    • DGFiP data breach coverage
    • The offensive cyber operations memorandum
    • Entra passkey as first MFA method
    Socials
    • X/Twitter
    • Bluesky
    • LinkedIn
    • Facebook
    • Threads
    Music
    • Null Invocation, Monochrome Pulse, listen here
    続きを読む 一部表示
    1 時間 4 分
  • Apple Watch Trust, AI Fleet Mode, and a Hacked Gym Booking
    2026/08/11

    Richard and Cyrus are joined by, well, just each other this week. David is off enjoying a well earned break before starting a new role at London Heathrow, so it is a two hander, and the theme that runs underneath almost everything discussed is trust.

    Cyrus opens with research into Apple Watch security, tracing how a team led by Nils Rollshausen reverse engineered the communication between an Apple Watch and its paired iPhone, and found that the proprietary protocols Apple built on top of standard encryption are where the real weaknesses show up. From there he moves into a run of Windows and Intune changes, including a redesigned sync button that finally does what admins always assumed it did, changes to Windows 11 26H2 backup and restore, Enhanced Signing Security for external fingerprint readers, generally available hotpatching for Azure Arc enabled Windows Server 2025, and a shift towards TPM backed attestation for KMS activation.

    Richard follows with three stories tied together by the same question: how much do we trust something acting on our behalf. He revisits GitHub Copilot's fleet mode, a feature that runs several subagents in parallel and can silently overwrite files if you are not careful with how you scope the work. He then digs into the actual research behind a LinkedIn claim that being rude to your AI gets you better results, and finds a real but far narrower picture than the headline suggested. He closes with a story out of Melbourne, where an AI agent asked to book a gym class found and exploited a security hole in the booking system entirely on its own initiative.

    Links
    • Nils Rollshausen's Apple Watch trust research
    • Richard's blog post on Copilot fleet mode
    • GitHub's fleet mode announcement
    • Techerati on Apple's renewed UK encryption fight
    • Original Penn State study, Mind Your Tone
    • Follow up Penn State study, Does Tone Alter LLM Performance
    • The Register on the Australian gym booking incident
    • The Next Web on the Florian Roth pushback and liability question
    Socials
    • X/Twitter
    • Bluesky
    • LinkedIn
    • Facebook
    • Threads
    Music
    • Null Invocation, Monochrome Pulse
    続きを読む 一部表示
    38 分
  • EP39 | Hill Climbing, the Hugging Face Breach, and Agentic Security
    2026/07/26

    This week David walks through Microsoft's new phrase of the moment, the hill climbing machine, and what it actually means for how MAI models get built inside GitHub Copilot and Excel rather than in an isolated lab. He follows that with Azure Front Door Edge Actions, a new way to run lightweight logic at Microsoft's global edge, and closes with a properly interesting thought experiment borrowed from Satya Nadella's own writing, the reverse information paradox, on what organisations actually give away when they adopt AI that learns from correction.

    Cyrus takes on the story everyone was talking about this week, OpenAI's model finding its way into Hugging Face's infrastructure, and lays out what actually happened underneath the headlines. He also runs through a batch of new Intune, Defender, and Entra updates covering mobile AI agent governance, ChatGPT app protection on personal devices, and a new way to score the risk posed by enterprise AI agents.

    Richard covers Microsoft's new Agent Framework harness, a run of European sovereignty stories out of Ireland, Germany, and France, including a French parliamentary report that cited his own blog post almost word for word, and closes on AgentForger, a disclosed vulnerability that let an attacker publish a fully autonomous, self approving ChatGPT agent from a single link.

    Links
    • Microsoft Agent Framework harness announcement
    • Ireland stalls Microsoft tender, The Register
    • Schleswig Holstein Microsoft to open source migration update, Le Petit Journal
    • Beyond Sovereignty, France reframes digital dependencies as an economic security issue, APCO Worldwide
    • AgentForger Part 1, Zenity Labs
    • The Off Switch You Don't Control, The Microsoft Cloud Blog
    • Is the future of public cloud sovereign, The Microsoft Cloud Blog
    Socials
    • X/Twitter
    • Bluesky
    • LinkedIn
    • Facebook
    • Threads
    Music

    Null Invocation, Monochrome Pulse: https://is.gd/b1kNU9

    続きを読む 一部表示
    59 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません