Skip to content
You can now search across every topic, entity and event.What's new
Microsoft
OrganisationUS

Microsoft

Global software and cloud giant; Azure, M365, Intune; DMA probe and US cloud sovereignty risk.

SharePoint remained under active exploitation through July 2026, the latest in a run of Microsoft patch emergencies that began with a 17-year-old Office remote-code flaw returning to the exploited-vulnerabilities list in April.

Last refreshed: 4 August 2026 · Appears in 5 active topics

Key Question

Microsoft admitted to the French Senate it cannot guarantee French data stays in France: what does that mean for its European cloud business?

Timeline for Microsoft

#12 29 Jul

Reported quarterly capex and revised its calendar-2026 capex estimate to ~$175bn

Data Centres: Boom and Backlash: The big four's combined capex holds near $732bn
#12 28 Jul

Dublin slips to 15% as growth heads north

Data Centres: Boom and Backlash
#12 22 Jul
View full timeline →

Background

Microsoft, founded by Bill Gates and Paul Allen in 1975, is among the world's most valuable companies by market capitalisation. Its Azure cloud platform competes with Amazon Web Services and Google Cloud for enterprise and AI workloads; GitHub Copilot is the most widely adopted AI coding assistant, and Microsoft 365 Copilot embeds generative AI across its Office suite.

The European Commission opened a Digital Markets Act cloud-gatekeeper probe against Azure in October 2025, alongside a parallel probe of AWS . Microsoft has told the French Senate it cannot guarantee French customer data on Azure would never be disclosed under US legal orders, the CLOUD Act exposure that leaves it ineligible for the EU's top sovereign-cloud procurement tier.

Its enterprise ubiquity across government and corporate networks makes it a persistent target: state-linked hacking groups and criminal actors alike probe its products for footholds, and its cloud and productivity suites now underpin AI deployment across most large organisations, which raises the stakes of every vulnerability and every data-sovereignty question it faces.

Key Issues
Patch emergencies

Microsoft's software stays under active fire

A 17-year-old Office remote-code-execution flaw returned to the US government's Known Exploited Vulnerabilities list on 14 April 2026 , the same week Russia's GRU was found hijacking home routers to harvest Microsoft 365 login credentials . SharePoint flaws kept the pressure on through the summer, with a patch deadline on 1 July and active exploitation still logged on 22 July .

The repeated cycle, an old bug resurfacing, a nation-state credential campaign, then a live SharePoint exploit still unresolved three weeks after its patch Deadline, illustrates why Microsoft's enterprise ubiquity is also its largest liability: its software sits deep enough in government and corporate networks that any flaw becomes a standing national-security concern rather than a routine bug.

Common Questions
Why did Kenya suspend the Microsoft data-centre project at Olkaria?
Kenya suspended the $1 billion Microsoft-G42 geothermal campus at Olkaria because the full 1 GW target would draw roughly a third of Kenya's entire installed national capacity of approximately 3 GW. President Ruto said building it would mean switching off half the country.Source: Lowdown data-centres update
What is Microsoft's out-of-band patch KB5091157 for?
KB5091157 is an emergency Windows Server patch issued by Microsoft in April 2026, fixing LSASS reboot loops on domain controllers with Privileged Access Management enabled. It affected Windows Server 2016 through 2025.Source: Microsoft / MSRC
Is Microsoft Azure safe from GRU hacking?
In April 2026 NCSC confirmed GRU Unit 26165 (APT28) was hijacking home routers to steal Microsoft 365 OAuth credentials. Microsoft services are a primary target for Russian state cyber operations.Source: Lowdown
What is the DMA cloud probe against Microsoft?
The European Commission opened a Digital Markets Act cloud gatekeeper investigation against Microsoft Azure and AWS in late 2025. The probe could mandate interoperability standards that lower switching costs for European customers. The US countered with a Section 301 investigation calling the DMA rules Economic warfare.Source: Lowdown
Will Microsoft's AI spending pay off?
Barclays analysis warns that sustained AI capital expenditure at current levels could significantly reduce Big Tech free cash flow. Whether enterprise AI revenue grows fast enough to justify the spending remains the central question for Microsoft investors.Source: Lowdown
How much is Microsoft making from AI in 2026?
Microsoft posted a record quarter in early 2026 driven by AI cloud revenue. Azure growth accelerated as enterprises migrated workloads to Microsoft's AI infrastructure, validating its massive capital expenditure.Source: Lowdown
Is Microsoft Azure subject to the US CLOUD Act?
Yes. Microsoft acknowledged before the French Senate in 2025 that it cannot guarantee French customer data on Azure would never be disclosed under US legal orders. This CLOUD Act exposure makes Azure ineligible for the highest tiers of EU sovereign cloud procurement under France's SecNumCloud and the EU's SEAL-3 framework.Source: French Senate / SecNumCloud
How did Handala hack 200,000 Stryker devices using Microsoft Intune?
Handala Hack obtained a single stolen Microsoft Intune administrator credential in March 2026. Using the Intune MDM console — with no malware deployed — they issued a factory-reset wipe command across 80,000–200,000 Stryker devices in 79 countries.Source: Stryker 8-K/A / Krebs on Security
What is Microsoft Copilot?
Microsoft offers two Copilot products: GitHub Copilot for developers and Microsoft 365 Copilot across Word, Excel, and other Office apps. Both use large language models to generate and edit content.
Source Material