Tag: microsoft
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/microsoft-teams-qr-code-phishing-protection/
-
Microsoft gesteht Update-Panne: Windows-11-Update macht den Desktop schwarz
Auch Mauszeigereinstellungen werden durch das Update auf vielen Windows-11-Systemen zurückgesetzt. Microsoft arbeitet an Korrekturen. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-windows-11-update-laesst-wallpaper-verschwinden-2609-212638.html
-
Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic.…
-
CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on…
-
Microsoft gesteht: Windows-11-Update lässt Wallpaper verschwinden
Auch Mauszeigereinstellungen werden durch das Update auf vielen Windows-11-Systemen zurückgesetzt. Microsoft arbeitet an Korrekturen. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-windows-11-update-laesst-wallpaper-verschwinden-2609-212638.html
-
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should-do-and-how-zscaler-can-help/
-
KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/
-
Microsoft-365-Security-Assessment Warum ein Audit mehr als den Secure-Score prüfen muss
In vielen Unternehmen ist Microsoft-365 längst keine Office-Suite mehr, sondern die zentrale Plattform für Identitäten, E-Mail, Zusammenarbeit, Geräteverwaltung und geschäftskritische Daten. Diese Konzentration macht den Arbeitsalltag effizient. Sie sorgt aber auch dafür, dass eine einzelne Fehlkonfiguration weitreichende Folgen haben kann: Ein zu großzügiger Gastzugriff, eine dauerhaft privilegierte Rolle oder eine unkontrollierte Anwendung reicht unter Umständen…
-
8 Signs Your School District Has Outgrown Its Web Content Filtering Solution
The digital classroom has changed dramatically over the past decade. Today’s K12 schools rely on 1:1 device initiatives, cloud-based platforms like Google Workspace and Microsoft 365, AI-powered educational tools, and hybrid learning models that extend instruction well beyond the classroom…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/8-signs-your-school-district-has-outgrown-its-web-content-filtering-solution/
-
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/
-
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows…
-
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
-
Zero-Trust-Strategie in Microsoft 365: Wie aus Prinzipien ein steuerbares Programm wird
Zero Trust in Microsoft 365 ist kein Lizenz- oder Toolprojekt, sondern ein steuerbares Sicherheitsprogramm. Entscheidend sind klare Schutzobjekte, belastbare Entscheidungswege, befristete Ausnahmen und messbare Nachweise damit aus technischen Kontrollen echte Risikoreduktion für das Unternehmen wird. Management Summary Zero Trust braucht Führung: Der Nutzen entsteht erst, wenn Geschäftsrisiko, technische Kontrolle und überprüfbarer Zielzustand zusammengeführt werden…. First…
-
Zero-Trust-Strategie in Microsoft 365: Wie aus Prinzipien ein steuerbares Programm wird
Zero Trust in Microsoft 365 ist kein Lizenz- oder Toolprojekt, sondern ein steuerbares Sicherheitsprogramm. Entscheidend sind klare Schutzobjekte, belastbare Entscheidungswege, befristete Ausnahmen und messbare Nachweise damit aus technischen Kontrollen echte Risikoreduktion für das Unternehmen wird. Management Summary Zero Trust braucht Führung: Der Nutzen entsteht erst, wenn Geschäftsrisiko, technische Kontrolle und überprüfbarer Zielzustand zusammengeführt werden…. First…
-
Zero-Trust-Strategie in Microsoft 365: Wie aus Prinzipien ein steuerbares Programm wird
Zero Trust in Microsoft 365 ist kein Lizenz- oder Toolprojekt, sondern ein steuerbares Sicherheitsprogramm. Entscheidend sind klare Schutzobjekte, belastbare Entscheidungswege, befristete Ausnahmen und messbare Nachweise damit aus technischen Kontrollen echte Risikoreduktion für das Unternehmen wird. Management Summary Zero Trust braucht Führung: Der Nutzen entsteht erst, wenn Geschäftsrisiko, technische Kontrolle und überprüfbarer Zielzustand zusammengeführt werden…. First…
-
Microsoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnel
Tags: microsoftFirst seen on scworld.com Jump to article: www.scworld.com/news/microsoft-identifies-terminalfix-campaign-spreading-python-reverse-tunnel
-
Microsoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnel
Tags: microsoftFirst seen on scworld.com Jump to article: www.scworld.com/news/microsoft-identifies-terminalfix-campaign-spreading-python-reverse-tunnel
-
New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight…
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users
The Spring Ring operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users
-
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
HiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/
-
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw/
-
255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance employment platform to distribute malicious Microsoft Excel files to roughly 80,000 users. Federal prosecutors allege that Searzhudin Tamirlanovich Aktulaev, 40, orchestrated the campaign between June 2016 and November 2017,…
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…
-
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/
-
Huntress and blueAPACHE expand partnership around Microsoft security
Tags: microsoftFirst seen on scworld.com Jump to article: www.scworld.com/news/blueapache-expands-cybersecurity-partnership-with-huntress

