Tag: microsoft
-
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/
-
Gold für Coreview Tenant-Resilience for Microsoft-365″¯mit dem German-Stevie-Award-2026 ausgezeichnet
Coreview hat für seine Security-Lösung <> bei den bei den diesjährigen German-Stevie-Awards den goldenen Stevie-Award in der Kategorie ‘Business Technology Solution Identitäts- und Zugriffssicherheitslösung” gewonnen. Für die Fachjury bietet Coreview eine ‘ausgereifte Lösung, die der zunehmenden Komplexität moderner Cloud-Umgebungen wirksam begegnet und gleichzeitig die Governance und Ausfallsicherheit verbessert.” Coreview ist […] First seen on netzpalaver.de…
-
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
-
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The most common way into a company last year was to ask.A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and…
-
Massive Microsoft 365 outage causes auth issues, service failures
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/
-
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
Tags: advisory, attack, authentication, cve, cyber, microsoft, rce, remote-code-execution, vulnerabilityA public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange Server. This repository highlights CVE-2026-62911, an Exchange authentication-bypass vulnerability disclosed following Pwn2Own Berlin 2026. Defenders should treat the published code as unverified until it is independently validated in an isolated laboratory environment. Both the official advisory and…
-
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/
-
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/
-
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming >>Microsoft Defender Antivirus is turned off,<< even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security…
-
Microsoft asks users to ignore ‘Antivirus is turned off’ errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/
-
Virenschutz angeblich aus: Microsoft Defender spielt falsche Warnmeldung aus
Einige Windows-Nutzer erhalten seit Wochen Warnmeldungen vom Microsoft Defender, dass der Virenschutz inaktiv sei. Das ist jedoch ein Anzeigefehler. First seen on golem.de Jump to article: www.golem.de/news/virenschutz-angeblich-aus-microsoft-defender-spielt-falsche-warnmeldung-aus-2608-212431.html
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints. First seen on wired.com Jump to article: www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/
-
Rethink Hybrid Identity: It Is Not the Destination
<div cla How We Got Here Hybrid identity emerged as a byproduct of enterprise cloud and SaaS adoption. As organizations adopted cloud productivity platforms, collaboration services, SaaS applications, and cloud-hosted business systems, hybrid identity became a practical transition model. It enabled enterprises to bridge existing on-premises identity infrastructure with newly adopted cloud services. The mechanism…
-
Ehemaliger Medusa-Partner setzt auf neue Ransomware StormEncryptor
Microsoft entdeckte die neue Ransomware StormEncryptor, eingesetzt von der mutmaßlich chinesischen Gruppe Storm-1175, die zuvor auf Medusa setzte. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-stormencryptor
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active…
-
Windows XP gratis: Wie ein einziger geleakter Firmenschlüssel Microsofts Schutz aushebelte
First seen on t3n.de Jump to article: t3n.de/news/windows-xp-key-kein-hack-1759839/
-
Windows XP gratis: Wie ein einziger geleakter Firmenschlüssel Microsofts Schutz aushebelte
First seen on t3n.de Jump to article: t3n.de/news/windows-xp-key-kein-hack-1759839/
-
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as…
-
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute…
-
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, microsoft, sql, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let…
-
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/
-
OpenAI Warns AI-Enabled Cyberattacks Will Surge, Calls for Global Cyber Defense
Tags: ai, cisco, crowdstrike, cyber, cyberattack, defense, google, government, infrastructure, microsoft, openai, technologyOpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization urges industries, governments, technology providers, and critical infrastructure operators to work together in a coordinated global response to cyber defense. In an open letter signed by over 100 organizations, including Microsoft, Google, AWS, Cisco, Cloudflare, CrowdStrike,…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
100-plus companies call for ‘global surge’ in AI-powered cyber defense
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-cyber-defense-global-surge/
-
KQL queries for detecting risky Entra ID sign-ins in Sentinel
Risky sign-ins are one of the most useful identity signals you can monitor in Microsoft Sentinel, especially if your environment is heavily dependent on Microsoft 365 and Entra ID for access. For UK SMEs, the value is not just in spotting suspicious logons. It is in getting enough context to decide quickly whether an account……

