Researchers Flag Abuse and Data-Leak Risks in SQL Server 2025 AI Features
Microsoft introduced new features in SQL Server 2025 that connect to external AI models, allowing businesses to run AI workflows directly on database content. Cybersecurity firm SpecterOps said such integrations also expand the database attack surface and could bypass traditional monitoring focused on anomalous queries or file transfers.
The latest SpecterOps research found that attackers could abuse SQL Server 2025 stored procedures and external AI model connections to exfiltrate sensitive data disguised as legitimate HTTPS traffic, making detection and blocking more difficult. Reports did not specify the disclosure date, the number of affected companies or any financial losses. The current focus is on the potential risks arising from the features’ design.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →