Tag: microsoft
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026. The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling. The group was previously associated with…
-
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/
-
Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello…
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.”The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, First seen on thehackernews.com…
-
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/august-2026-patch-tuesday-forecast/
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
Swiss government SharePoint breach compromised 200 accounts
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
-
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/
-
Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt
Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert. First seen on golem.de Jump to article: www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommunikation-ueber-sharepoint-gehackt-2608-211659.html
-
Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges
Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-bug-bounty-payouts-20-million/
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…
-
TENEX.ai Launches Turn-Key Agentic SecOps Platform, Deployable in a Week
TENEX.ai announced commercial availability of a turn-key, fully agentic, human-led Security Operations platform at Black Hat 2026, positioning it as a new category the company calls >>Fully-Agentic, Human-Led Security Operations.<< The platform deploys on Google SecOps or Microsoft Sentinel and can go operational in as little as seven days, without replacing existing security infrastructure, deploying..…
-
Hacker greifen 120 Unternehmen über offizielle Microsoft-Dienste mit Phishing-Mails an
Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies hat eine neue Phishing-Taktik von Angreifern aufgedeckt und analysiert, die sich Microsofts Infrastruktur zunutze macht und deren Vertrauenswürdigkeit ausnutzt. Vom 25. Juni bis in die zweite Juliwoche identifizierte CPR mehr als 200 Phishing-E-Mails, die sich an Nutzer in rund 120 Organisationen richteten und dabei…
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Angriff gegen 120 Unternehmen Kampagne nutzt echte Microsoft-Anmeldung
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-microsoft-teams-echte-login-seite-boesartige-app-berechtigungen-a-2fa1636d91b31c8388f4555881a3fc9f/
-
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries, highlighting the global nature of coordinated vulnerability disclosure efforts that help protect Microsoft customers worldwide. This represents significant growth over…
-
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial…
-
Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks. First seen on hackread.com Jump to article: hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
-
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-russian-hackers-hotel-wifi/
-
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
-
Microsoft Project Perception Enters Public Preview: What Security Teams Should Know
Microsoft’s Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview: What Security Teams Should Know appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-project-perception-preview/
-
KnowBe4 erweitert Agentensicherheit mit AgentManager auf Claude von Anthropic
KnowBe4 baut die Sicherheit für KI-Agenten auf Claude von Anthropic durch den Agent-Risk-Manager aus. Die neue Integration bietet Echtzeit-Transparenz und automatisierte Bedrohungserkennung zur Steuerung autonomer KI-Agenten. KnowBe4 erweitert dadurch seine Governance-Ebene und baut dabei auf der bestehenden nativen Unterstützung für Microsoft-Copilot auf. Eine knappe Mehrheit von 58 Prozent an befragten Führungskräften im Bereich Cybersicherheit geben laut dem…
-
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in. First seen on therecord.media Jump to article: therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
-
Bug-Bounty-Rekord: Microsoft verteilt 20 Millionen US-Dollar an IT-Forscher
Microsoft hat einen neuen Rekord bei der Ausschüttung seiner Bug-Bounty-Prämien aufgestellt. Für die Forscher war das aber nicht unbedingt von Vorteil. First seen on golem.de Jump to article: www.golem.de/news/bug-bounty-rekord-microsoft-verteilt-20-millionen-us-dollar-an-it-forscher-2608-211580.html
-
Barracuda Networks Shows How AI Agents Can Compromise Business Email
Barracuda Networks shows how attackers could hijack Microsoft Copilot to access sensitive emails, impersonate executives and execute convincing business email compromise attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/barracuda-networks-shows-how-ai-agents-can-compromise-business-email/
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
Microsoft shortens NuGet API key lifetime to improve supply chain security
Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…

