Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: 900% Rise in Critical Microsoft Vulnerabilities

Druva
10/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


But the problem there is what was remaining. All the critical vulnerabilities went up and the critical vulnerabilities for Azure and Dynamics also went up. So it's not just in isolation, you know, and it's a very big number by all means. And Microsoft attributes a lot of these things to even these threat actors, these criminal organizations using A.I. to attack us, even looking at encryptions and exfiltrations. So there's a digital defense report that's released every year. That number of encryptions and exfiltrations started at 16 percent. Then it went up to twenty three or twenty six percent. And last year it went up another seven percent. So you look at these continued impacts to the data. And if we are thinking about backup and only backup, if we're if we're lucky, we have so many companies that don't even understand that they they are responsible for their own data and that they do have to back it up. But if we're not prepared to help our team answer, what do we do with encryptions and exfiltrations and that pattern and what data do we need to help address that? That's a lot of where we want to, you know, the conversations that we're having with, you know, with our customers and building out playbooks and working through run books with them.

TL;DR

  • Critical Microsoft vulnerabilities surged 900% even as total vulnerability counts fell 6%, with Azure and Dynamics specifically impacted by the rise.
  • Criminal organizations are using AI to drive a steady increase in ransomware encryption and data exfiltration events, per Microsoft's Digital Defense Report.
  • Backup-only strategies leave organizations unprepared — Druva argues teams must have playbooks and run books to respond to encryption and exfiltration incidents.

Summary

This short clip, excerpted from a Druva webinar, highlights a striking trend in the Microsoft vulnerability landscape: while the total number of reported vulnerabilities across the Microsoft ecosystem declined by six percent last year, the critical and actively exploited vulnerabilities rose sharply — including a 900% surge in certain categories — with Azure and Dynamics specifically called out. Speaker Vanessa ties this escalation directly to criminal organizations leveraging AI to accelerate attacks, particularly encryption-based ransomware and data exfiltration campaigns. Data from Microsoft's annual Digital Defense Report shows that the rate of encryption and exfiltration incidents has climbed steadily — from 16% to 23–26%, and then up another seven percent in the most recent reporting period. The segment closes with a pointed challenge to organizations that rely solely on backup: Druva argues that backup alone is insufficient when teams cannot answer what to do when encryption or exfiltration occurs. The conversation Druva is driving with customers centers on building incident response playbooks and run books that address these evolving threat patterns — positioning the company as a strategic partner in cyber resilience, not just a data protection vendor.

Chapters

0:00 - The 900% Vulnerability Surge
0:26 - AI-Driven Threat Actors
0:39 - Encryption & Exfiltration Trends
0:59 - Beyond Backup: Building Playbooks

Key Quotes

0:00 "Look at this nine hundred percent. That sounds like a lot. And it is the overall number of vulnerabilities for the Microsoft ecosystem actually went down by six percent last year."
0:26 "Microsoft attributes a lot of these things to even these threat actors, these criminal organizations using A.I. to attack us, even looking at encryptions and exfiltrations."
0:59 "If we are thinking about backup and only backup, if we're lucky, we have so many companies that don't even understand that they are responsible for their own data and that they do have to back it up."

FAQ

Why did critical Microsoft vulnerabilities rise even though total vulnerabilities went down?

According to the clip, while the overall count of Microsoft ecosystem vulnerabilities dropped 6%, the remaining vulnerabilities skewed heavily toward critical severity. Azure and Dynamics saw their own increases in critical flaws, and threat actors — increasingly using AI — are targeting these high-value weaknesses for encryption and exfiltration attacks.

What does Druva recommend beyond traditional backup?

Druva advocates for building incident response playbooks and run books that specifically address encryption and exfiltration scenarios. The argument is that many organizations don't even recognize their own data responsibility, let alone have a structured response plan when a breach occurs.


Categories:
  • » Webinar Library » Druva
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Data Protection
  • Security Operations
  • Cloud Security
  • Best Practices
  • Microsoft vulnerability trends
  • Critical vulnerability surge
  • AI-assisted cyberattacks
  • Ransomware and data exfiltration
  • Incident response planning
  • Cyber resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: 900% Rise in Critical Microsoft Vulnerabilities

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version