Tag: microsoft
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social…
-
Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft…
-
Microsoft’s Project Zenith puts large AI models directly on developer PCs
Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/microsoft-project-zenith-windows-11-experience/
-
Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal administration. This initiative, announced to the Federal Council on September 2, aims to establish an open-source workplace platform that will operate alongside Microsoft 365 without…
-
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
-
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.The activity, which mainly singles out directors, vice presidents, and other executive staff First seen on thehackernews.com Jump to…
-
Coreview auf der it-sa 2026 Microsoft-365-Sicherheit als Fundament für den KI-Einsatz
Coreview präsentiert auch in diesem Jahr auf der it-sa seine Lösungen für den Schutz und das Management von Microsoft-365-Tenants. Auf ihrem Stand (Halle 7, Stand 7-545) zeigen die Experten, wie sich Unternehmen vor Manipulationen, Fehlkonfigurationen und dem Verlust unternehmenskritischer Microsoft-365-Einstellungen schützen können und damit die Grundlage für den sicheren Einsatz von KI-Tools wie Microsoft-Copilot schaffen.…
-
Is Hotel WiFi Safe?
Hotel Wi”‘Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/is-hotel-wifi-safe/
-
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, enabling attackers to steal browser data, hijack sessions, manage files and execute shell commands on compromised endpoints. Unlike a conventional initial-access malware strain, PEEP requires attackers to already possess administrative privileges or code-execution access on a…
-
158 Namenswechsel für 72 Dienste dieses Tool zeigt das volle Ausmaß
First seen on t3n.de Jump to article: t3n.de/news/microsoft-rebranding-rebrand-registry-namenswechsel-1759308/
-
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.The company named the four programs ProManager, WinUpdate, SoftManager, and First seen on thehackernews.com…
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Data dive: Mapping NHS hyperscaler dependence
Mapping NHS DNS data reveals a heavy reliance on US hyperscalers, with Microsoft 365 routing email and infrastructure for the vast majority of trusts in a tangled web of connections First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649921/Data-dive-Mapping-NHS-hyperscaler-dependence
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.”Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security…
-
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/
-
Researcher Releases Exploit of Claimed CrowdStrike Falcon Zero-Day
The security researcher who for much of the year has haunted Microsoft by publishing zero-day vulnerabilities without disclosing them to the IT giant first this week dropped another exploit, this time one that targets CrowdStrike’s Falcon endpoint security platform. The researcher who goes by a number of names, including Nightmare-Eclipse, Chaotic Eclipse, MSNightmare, and.. First…
-
Exchange Online outage causes email delays, ‘Server busy’ errors
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/
-
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in…
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations.…
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/

