Tag: microsoft
-
Microsoft SharePoint Server 0-Day Exploit Targets African Treasury, Companies, and University
A sophisticated zero-day exploit campaign targeting unpatched vulnerabilities in Microsoft SharePoint Server has compromised approximately 400 organizations worldwide, with potential for a far higher victim count due to underreporting and delayed detections. The attacks, first identified last week by Dutch cybersecurity firm Eye Security, leverage critical flaws in on-premise SharePoint installations, allowing threat actors to…
-
Security-Coach von KnowBe4 wird in Microsoft.Edge for Business integriert
wird in Microsoft-Edge for Business integriert und liefert Sicherheitshinweise in Echtzeit bei riskantem Benutzerverhalten. Da Browser-Sicherheitsbedrohungen zunehmen, sollten Cybersicherheitsexperten weltweit Maßnahmen zur Risikominderung in Betracht ziehen. So hat ein Bericht von Menlo Security einen Anstieg von 140 Prozent bei browserbasierten Phishing-Angriffen festgestellt. Die Integration von und Microsoft-Edge for Business nutzt native Sicherheitssignale, […] First seen…
-
US Tops Hit List as 396 SharePoint Systems Compromised Globally
A total of 396 compromised Microsoft SharePoint systems have been identified globally, affecting 145 organizations across 41 countries in the wake of the ToolShell zero-day vulnerability First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/396-sharepoint-systems-compromised/
-
Datenschutz auf Unternehmens-Smartphones – Apple Intelligence mit Microsoft Intune deaktivieren
First seen on security-insider.de Jump to article: www.security-insider.de/apple-intelligence-mit-microsoft-intune-deaktivieren-a-018eea34c64da0f5e48b5ec7c7316764/
-
African Orgs Fall to Mass Microsoft SharePoint Exploits
The National Treasury of South Africa is among the half-dozen known victims in South Africa, along with other nations, of the mass compromise of on-premises Microsoft SharePoint servers. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/african-orgs-mass-microsoft-sharepoint-exploits
-
New Microsoft Guidance Targets Defense Against Indirect Prompt Injection
Microsoft has unveiled new guidance addressing one of the most pressing security challenges facing enterprise AI deployments: indirect prompt injection attacks. This emerging threat vector has become the top entry in the OWASP Top 10 for LLM Applications & Generative AI 2025, prompting the tech giant to develop a multi-layered defense strategy spanning prevention, detection,…
-
Coyote Trojan Turns Accessibility Into Attack Surface
Brazil-Targeting Malware Exploits Windows UIA to Evade Detection. A banking Trojan long confined to Brazil has become the first known malware to exploit Microsoft’s UI Automation framework to extract credentials, signaling a new tactic that may evade conventional detection. Akamai’s findings point to a growing trend of attackers using legitimate system features. First seen on…
-
Nimble ‘Gunra’ Ransomware Evolves With Linux Variant
The emerging cybercriminal gang, which initially targeted Microsoft Windows systems, is looking to go cross-platform using sophisticated, multithread encryption. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/nimble-gunra-ransomware-linux-variant
-
Microsoft Sentinel data lake: Unify signals, cut costs, and power agentic AI
First seen on thesecurityblogger.com Jump to article: www.thesecurityblogger.com/microsoft-sentinel-data-lake-unify-signals-cut-costs-and-power-agentic-ai/
-
EU-Kommission darf MS365 einsetzen
Tags: microsoftÜberraschende Wende: Die Europäische Kommission darf Microsoft 365 offiziell einsetzen, nachdem sie nach Nachbesserungen mit den EU-Datenschutzbestimmungen im Einklang ist. Der EU-Datenschutzbeauftragte hat das betreffende Verfahren eingestellt. Datenschutzbeauftragter gegen EU-Kommission Den Hintergrund hatte ich im Blog-Beitrag EU-Datenschützer: EU-Kommission verstößt mit Microsoft … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/29/eu-kommission-darf-ms365-einsetzen/
-
Microsoft Edge now an ‘AI-powered browser’ with Copilot Mode
Microsoft has introduced Copilot Mode, an experimental feature designed to transform Microsoft Edge into a web browser powered by artificial intelligence (AI). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-edge-now-an-ai-powered-browser-with-copilot-mode/
-
Lazarus Subgroup ‘TraderTraitor’ Targets Cloud Platforms and Contaminates Supply Chains
Tags: cloud, cyber, cybersecurity, group, lazarus, mandiant, microsoft, north-korea, supply-chain, threatThe North Korean state-sponsored advanced persistent threat (APT) known as TraderTraitor, a subgroup of the notorious Lazarus Group, has emerged as a formidable actor specializing in digital asset heists. Tracked under aliases such as UNC4899, Jade Sleet, TA444, and Slow Pisces by various cybersecurity firms including Mandiant, Microsoft, Proofpoint, and Unit42, TraderTraitor operates under the…
-
Microsoft Teams Introduces New Join Bar to Help Users Join Meetings on Time
Microsoft Teams is rolling out a new meeting join banner designed to streamline the meeting experience for users who have committed to attending scheduled sessions. The feature, which launched in mid-July 2025, represents the company’s continued effort to enhance productivity and reduce meeting-related friction for its millions of users worldwide. Enhanced Meeting Access Experience The…
-
Microsoft-Sicherheitslücke – China warnt vor ‘Diffamierung”
First seen on security-insider.de Jump to article: www.security-insider.de/china-warnt-nach-hacker-angriffen-auf-microsoft-software-a-8d896f95c7fed98fa2b30f4d1c286aba/
-
New macOS Vulnerability Allows Attackers to Steal Private Files by Bypassing TCC
Microsoft Threat Intelligence has uncovered a critical macOS vulnerability that enables attackers to bypass Apple’s Transparency, Consent, and Control (TCC) framework, potentially exposing sensitive user data including files protected by privacy controls and information cached by Apple Intelligence. Vulnerability Overview The newly discovered vulnerability, dubbed >>Sploitlight
-
Hackers Exploit IIS Servers with New Web Shell Script for Full Remote Control
Tags: control, cyber, exploit, hacker, incident response, Internet, microsoft, middle-east, service, windowsSecurity researchers have examined a complex online shell script called UpdateChecker.aspx that was installed on compromised Internet Information Services (IIS) servers in response to a notable increase in cyberthreats directed at Microsoft Windows installations. This analysis stems from a follow-up investigation by FortiGuard’s Incident Response Team into a prolonged intrusion at a Middle East critical…
-
SharePoint Attacks Should Lead Companies To ‘Rethink’ Risk Of On-Prem Vs. Cloud: Expert
While organizations may have a variety of reasons for sticking with on-premises Microsoft SharePoint servers, widespread attacks targeting the servers are grounds to “re-do their risk calculus” and newly explore cloud-based options, according to former FBI cybersecurity leader Cynthia Kaiser. First seen on crn.com Jump to article: www.crn.com/news/security/2025/sharepoint-attacks-should-lead-companies-to-rethink-risk-of-on-prem-vs-cloud-expert
-
Microsoft Says SharePoint Attacks Now Include Ransomware
A China-linked threat actor has been observed exploiting SharePoint servers to deliver ransomware, according to Microsoft researchers, in the latest sign of worsening attacks against on-premises SharePoint Server customers. First seen on crn.com Jump to article: www.crn.com/news/security/2025/microsoft-says-sharepoint-attacks-now-include-ransomware
-
10 Major Cyberattacks And Data Breaches In 2025 (So Far)
Major cyberattacks in 2025 so far have included the Microsoft SharePoint Server “ToolShell” attacks, the ransomware attack against IT distributor Ingram Micro and a series of Scattered Spider attacks targeting numerous industries. First seen on crn.com Jump to article: www.crn.com/news/security/2025/10-major-cyberattacks-and-data-breaches-in-2025-so-far
-
Victims Mounting In Microsoft SharePoint Attacks: Researchers
More than 400 systems have been compromised so far in the widespread cyberattacks exploiting vulnerabilities in Microsoft SharePoint servers, according to researchers at Eye Security. First seen on crn.com Jump to article: www.crn.com/news/security/2025/victims-mounting-in-microsoft-sharepoint-attacks-researchers
-
Microsoft uncovers macOS flaw allowing bypass TCC protections and exposing sensitive data
Microsoft found a macOS flaw letting attackers access private data from protected areas like Downloads and Apple Intelligence caches. Microsoft Threat Intelligence researchers discovered a macOS vulnerability that could allow attackers to steal private data of files normally protected by Transparency, Consent, and Control (TCC). Apple’s Transparency, Consent, and Control framework in macOS is designed…
-
Microsoft spotlights Apple bug patched in March as SharePoint exploits continue
Look over there! First seen on theregister.com Jump to article: www.theregister.com/2025/07/28/microsoft_spots_apple_bug/
-
Windows auf veraltete libcurl-Bibliotheken in Programmen überprüfen
Ich hatte es schon mal im Blog: Microsoft liefert die cURL-Bibliothek häufiger mit veralteten Versionen, die Sicherheitslücken aufweisen, aus. Auch Software-Pakete kommen mit uralten libcurl-Dateien daher. Wie kann ich prüfen, ob da irgendwelche Altlasten auf meinen Systemen schlummern? Was sind … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/29/software-und-die-veralteten-libcurl-bibliotheken/
-
Microsoft SharePoint Hackers Switch Gears to Spread Ransomware
Threat actors exploit SharePoint flaws to access internal systems, steal sensitive data, and carry out surveillance, impersonation, and extortion. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/microsoft/sharepoint-vulnerabilities-exploitation/
-
ToolShell: Uncovering Five Critical Vulnerabilities in Microsoft SharePoint
Security researchers from Kaspersky have detailed a sophisticated exploit chain dubbed >>ToolShell,
-
macOS Sploitlight flaw leaks Apple Intelligence data
Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-macos-sploitlight-flaw-leaks-apple-intelligence-data/
-
Windows 11 is a minefield of micro-aggressions in the shipping lane of progress
A better minesweeper is needed. Time for an intervention to save Microsoft from itself First seen on theregister.com Jump to article: www.theregister.com/2025/07/28/windows_11_is_a_minefield/
-
OpenAI prepares GPT-5 for roll out
OpenAI’s ChatGPT-5 could drop in the coming days, and it could be one of the best models from the Microsoft-backed startup. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openai-prepares-gpt-5-for-roll-out/
-
Microsoft will stop supporting Windows 11 22H2 in October
Microsoft has reminded customers today that the last supported editions of Windows 11 22H2 will reach their end of servicing on October 14. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-will-stop-supporting-windows-11-22h2-in-october/

