Mark RadarMARK RADAR
About
EN
Sign in

Researchers Flag Abuse and Data-Leak Risks in SQL Server 2025 AI Features

1 reports · First detected 2026-06-29 · Last active 2026-06-29

Microsoft introduced new features in SQL Server 2025 that connect to external AI models, allowing businesses to run AI workflows directly on database content. Cybersecurity firm SpecterOps said such integrations also expand the database attack surface and could bypass traditional monitoring focused on anomalous queries or file transfers.

The latest SpecterOps research found that attackers could abuse SQL Server 2025 stored procedures and external AI model connections to exfiltrate sensitive data disguised as legitimate HTTPS traffic, making detection and blocking more difficult. Reports did not specify the disclosure date, the number of affected companies or any financial losses. The current focus is on the potential risks arising from the features’ design.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)