Tag: microsoft
-
Nutzerbeschwerden: Kopierfunktion in Excel nach Office-Update kaputt
Im Netz häufen sich Beschwerden von Nutzern, die in Excel nicht mehr kopieren können. Ursache scheint ein Bug im neuen Microsoft-Office-Update zu sein. First seen on golem.de Jump to article: www.golem.de/news/nutzerbeschwerden-kopierfunktion-in-excel-nach-office-update-kaputt-2609-212865.html
-
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, vulnerability, windowsU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a…
-
Microsoft fixes bug that wiped Windows desktop settings
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/
-
12 Best Application Control Allowlisting Tools Compared (2026): Features Pricing
Quick Answer: For dedicated deny-by-default allowlisting, ThreatLocker and Airlock Digital lead in 2026; Microsoft WDAC/AppLocker is the free native option for Windows estates with engineering capacity; CyberArk and BeyondTrust pair control with privilege management. Pricing is typically per endpoint; Microsoft’s is bundled. Application control flips endpoint defense from “block known bad” to “allow only known…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5. Best Apple pricing: Mosyle, with a free tier that genuinely works. Best Apple depth: Jamf. Best published mid-market pricing: ManageEngine, Hexnode, and Scalefusion. Best rugged: SOTI. Deploying dedicated MDM allows organizations to enforce policy baseline compliance and device health verification within a […]…
-
The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5, which means most organizations reading this already own it. Best published pricing: ManageEngine. Best Apple depth: Jamf. Best rugged and purpose-built devices: SOTI and 42Gears. Best cross-platform enterprise: Omnissa. Unified endpoint management platforms allow security and IT teams to govern mobile devices, […]…
-
Shieldcrash: Forscher ärgert Microsoft mit neuem Defender-Exploit
Microsofts High-Quality-Update gegen den Shieldbreak-Exploit ist offenbar wenig effektiv. Ein frisch geleakter Exploit umgeht den Schutz. First seen on golem.de Jump to article: www.golem.de/news/shieldcrash-forscher-aergert-microsoft-mit-neuem-defender-exploit-2609-212855.html
-
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to…
-
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/
-
Microsoft Fixes 974 CVEs in Record Patch Tuesday Release
Microsoft fixed a record 974 CVEs for September’s Patch Tuesday, including two actively exploited Windows flaws. Most of the vulnerabilities addressed in the September release affect Windows, but the update also covers Office, SQL Server, Exchange Server, SharePoint Server, Azure and developer tools. Microsoft urged customers to apply the updates quickly and specifically called out..…
-
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-phishing-credential-theft-screenconnect/
-
Microsoft’s September Patch Tuesday Fixes Nearly 1,000 Flaws, Including 2 Exploited Zero-Days
Microsoft’s September 2026 Patch Tuesday fixes nearly 1,000 vulnerabilities, including two Windows zero-days already exploited in attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-september-2026-patch-tuesday-zero-days/
-
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, First seen on thehackernews.com Jump to…
-
Zero Day Initiative (ZDI) von TrendAI fast den Rekord-Patchday von September zusammen
Rekord-Patchday September 2026: Microsoft behebt fast 1.000 CVEs, Adobe 172 Lücken. Zero-Days und 20 potenziell wormable Schwachstellen im Fokus. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/zero-day-initiative-zdi-von-trendai-fast-den-rekord-patchday-von-september-zusammen/a46368/
-
Patch Tuesday: Microsoft updates address almost 1,000 flaws
Microsoft has released another record-breaking Patch Tuesday update with almost 1,000 flaws in scope First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650022/Patch-Tuesday-Microsoft-updates-address-almost-1000-flaws
-
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
-
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/
-
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/
-
Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
A human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration to impersonate internal IT or helpdesk staff, persuade employees to grant remote control of their PCs, and then move toward critical enterprise infrastructure. The campaign does not exploit a Microsoft Teams vulnerability. Instead, it weaponizes trust in familiar support workflows, combining Teams chats…
-
Windows Server 2025 changes causing app crashes
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced
Best value overall: Microsoft Defender for Endpoint, if you hold Microsoft 365 E5, you already own competitive enterprise endpoint protection and the marginal cost is zero. Best published pricing: Bitdefender and ESET, both of which let you budget without a sales call. Best detection: CrowdStrike. Best cleanup tool: Malwarebytes. One vendor on the standard […]…
-
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social…
-
Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft…

