Tag: microsoft
-
Microsoft Accelerates Quantum-Safe Push with New Timeline
Microsoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC) First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-accelerates-quantumsafe/
-
Microsoft Defender: Ransomware-Banden nutzen BlueHammer-Lücke aus
Ransomware-Erpresser nutzen die BlueHammer-Schwachstelle (CVE-2026-33825) in Microsoft Defender aus, um SYSTEM-Rechte zu erlangen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-defender-ransomware-bande
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
Microsoft wants to stop unwanted bots from entering Teams meetings
A new Microsoft Teams admin policy, Manage external bots and their access to meetings, gives organizations greater visibility and control over external bots in meetings. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/01/microsoft-teams-bot-detection-and-protection/
-
Microsoft dismantles StegoAd campaign using malicious Edge extensions
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-dismantles-stegoad-campaign-using-malicious-edge-extensions
-
Microsoft extends Windows Server 2022 hotpatching to 2027
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-extends-windows-server-2022-hotpatching-to-2027
-
Microsoft accelerates quantum-safe roadmap as risks grow
Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today’s encryption standards sooner than previously expected. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-accelerates-quantum-safe-roadmap-as-risks-grow/
-
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no…
-
Windows 10 bleibt länger sicher Microsoft verschiebt Support-Ende um ein Jahr
First seen on t3n.de Jump to article: t3n.de/news/windows-10-support-ende-verschoben-2027-1749639/
-
Microsoft adds smarter bot protection to Teams meetings
Tags: microsoftMicrosoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/mircosoft-adds-smarter-bot-protection-to-teams-meetings/
-
PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server
A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses left unaddressed by the original patch: the mitigation was limited to the SMB client path, and recent SMB features let attackers coerce privileged…
-
Windows BlueHammer flaw now exploited by ransomware gangs
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs/
-
Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces. Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named…
-
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.Microsoft says Google removed it from the store after responsible disclosure. The…
-
Microsoft extends Windows Server 2022 hotpatching until October 2027
Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-extends-windows-server-2022-hotpatching-until-october-2027/
-
StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
Microsoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever malicious extension campaigns it’s ever documented. The operation, named StegoAd, ran 119 extensions on the Edge Add-ons store, racked up roughly 2.6 million installs,…
-
Microsoft Edge: Malware in millionenfach installierten Browser-Add-ons entdeckt
Forscher haben in 119 Browsererweiterungen mit zusammen 2,6 Millionen Installationen Malware gefunden – obwohl sie ziemlich gut versteckt war. First seen on golem.de Jump to article: www.golem.de/news/microsoft-edge-malware-in-millionenfach-installierten-browser-add-ons-entdeckt-2606-210295.html
-
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud.The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat…
-
Microsoft 365 Apps RCE Vulnerability Lets Attackers Execute Code via Malicious Excel Files
A newly disclosed remote code execution (RCE) vulnerability in Microsoft 365 Apps is raising concerns in enterprise environments. Attackers can exploit malicious Excel documents to execute arbitrary code on target systems. This vulnerability, tracked as CVE-2025-60727, arises from an out-of-bounds read condition (CWE-125) in Microsoft Excel’s file-parsing mechanism, allowing threat actors to trigger memory corruption…
-
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails
Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has been running since April 2026. The targets are specific: device names observed across compromised environments include strings like…
-
Security News This Week: LastPass Users Had Their Data Stolen”, Again
Plus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-lastpass-users-had-their-data-stolen-again/
-
Microsoft Extends Windows 10 Security Updates to 2027
Microsoft extended Windows 10 security updates for personal devices through Oct. 12, 2027, giving users more time to upgrade. The post Microsoft Extends Windows 10 Security Updates to 2027 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-10-security-updates-2027/
-
CVE-2026-42824 in Microsoft 365 Copilot Enterprise – Copilot-Lücke SearchLeak ermöglicht Datendiebstahl per Klick
First seen on security-insider.de Jump to article: www.security-insider.de/searchleak-microsoft-copilot-enterprise-cve-2026-42824-a-cdcfe6e6b3a819ae4dbb8d3b5387465f/
-
Microsoft Defender vs Bitdefender: Compare Antivirus Software in 2026
Compare Microsoft Defender and Bitdefender across pricing, features, support, and business use cases in 2026 to find the best antivirus solution. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/microsoft-defender-vs-bitdefender/
-
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says.The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear.The lure…
-
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/mirage2fa-phishing-kit-microsoft-365-html-smuggling/
-
Doppelschlag auf SharePoint: Zwei Ransomware-Gruppen greifen zeitgleich an
Eine Untersuchung von Microsoft zeigt, dass zwei unterschiedliche Angreifer parallel Schwachstellen in lokalen SharePoint-Servern ausnutzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/sharepoint-zwei-ransomware-gruppen
-
Cybercrime-as-a Microsoft und BKA gehen gegen Amadey und StealC vor
Microsoft, BKA, Europol und weitere Partner sind gegen eine ganze Cybercrime-Maschinerie vorgegangen. First seen on computerbase.de Jump to article: www.computerbase.de/news/internet/cybercrime-as-a-service-microsoft-und-bka-gehen-gegen-amadey-und-stealc-vor.98107
-
Microsoft gives Windows 10 users an unexpected extra year of free security updates
Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/microsoft-windows-10-free-security-updates-esu-program/

