Tag: microsoft
-
Microsoft will stop supporting Windows 11 22H2 in October
Microsoft has reminded customers today that the last supported editions of Windows 11 22H2 will reach their end of servicing on October 14. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-will-stop-supporting-windows-11-22h2-in-october/
-
Inside Laundry Bear: Unveiling Infrastructure, Tactics, and Procedures
Dutch intelligence agencies AIVD and MIVD, alongside Microsoft Threat Intelligence, have identified Laundry Bear also tracked as Void Blizzard as a sophisticated Russian state-sponsored advanced persistent threat (APT) group active since at least April 2024. This actor has focused on espionage operations against NATO countries, Ukraine, and various organizations including the Dutch police, a Ukrainian…
-
Sharepoint-Angriffe: Hacker umgehen Microsofts Patch mit nur einem Zeichen
Laufende Attacken auf Sharepoint-Instanzen versetzen die IT-Welt in Aufruhr. Ein neuer Bericht gewährt Einblicke in Microsofts Versäumnisse. First seen on golem.de Jump to article: www.golem.de/news/sharepoint-angriffe-hacker-umgehen-microsofts-patch-mit-nur-einem-zeichen-2507-198577.html
-
Microsoft’s software licensing playbook is a national security risk
The tech giant’s model is built around anticompetitive practices, the head of the Coalition for Fair Software Licensing argues. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-software-licensing-national-security/
-
Panne bei Copilot Search: Microsoft verweist auf Domain, die es gar nicht besitzt
Tags: microsoftDie betroffene Domain wird von einem chinesischen Registrar verwaltet und steht derzeit zum Verkauf. Microsoft hat die Panne inzwischen korrigiert. First seen on golem.de Jump to article: www.golem.de/news/panne-bei-copilot-search-microsoft-verweist-auf-domain-die-es-gar-nicht-besitzt-2507-198567.html
-
SHUYAL Emerges: Stealing Login Credentials from 19 Major Browsers
A sophisticated new information stealer named SHUYAL was recently discovered by Hybrid Analysis. It has demonstrated extensive capabilities in credential extraction from 19 different web browsers, including popular ones like Google Chrome, Microsoft Edge, Opera, Brave, and Yandex, as well as more specialized ones like Opera GX, Vivaldi, Chromium, Waterfox, Tor, Epic Privacy Browser, Comodo…
-
New “ToolShell” Exploit Targets SharePoint Servers for Full Takeover
Tags: attack, cve, cyber, exploit, microsoft, remote-code-execution, threat, vulnerability, zero-dayFortiGuard Labs has identified a critical new exploit chain dubbed >>ToolShell
-
Week in review: Microsoft SharePoint servers under attack, landing your first cybersecurity job
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft pins on-prem SharePoint attacks on Chinese threat actors As … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/07/27/week-in-review-microsoft-sharepoint-servers-under-attack-landing-your-first-cybersecurity-job/
-
Microsoft walks us through Copilot Search with a domain it doesn’t even own
Tags: microsoftMock-ups feature m365.com, which could be yours for a few bucks First seen on theregister.com Jump to article: www.theregister.com/2025/07/25/copilot_search_m365_snafu/
-
Warum europäische Cloud-Lösungen unverzichtbar sind
Der kürzlich veröffentlichte Bericht über die Stellungnahme von Microsoft Frankreich vor dem französischen Senat zeigt ein grundlegendes Problem für europäische Unternehmen und Behörden: Microsoft kann nicht garantieren, dass in der EU gespeicherte Daten vor dem Zugriff US-amerikanischer Behörden geschützt sind. Bei einer Anhörung am 10. Juni 2025 musste Anton Carniaux, Direktor für öffentliche und rechtliche…
-
Blame a leak for Microsoft SharePoint attacks, researcher insists
MAPP program to blame? First seen on theregister.com Jump to article: www.theregister.com/2025/07/26/microsoft_sharepoint_attacks_leak/
-
Microsoft to stop using China-based teams to support Department of Defense
The tech giant has relied on global workforce to support federal clients. First seen on arstechnica.com Jump to article: arstechnica.com/security/2025/07/microsoft-to-stop-using-china-based-teams-to-support-department-of-defense/
-
Microsoft Investigates Leak in Early Warning System Used by Chinese Hackers to Exploit SharePoint Vulnerabilities
Tags: breach, china, cyber, cybersecurity, exploit, flaw, government, hacker, international, law, leak, microsoft, software, vulnerabilityChinese laws requiring vulnerability disclosure to the government create transparency issues and potential conflicts for international cybersecurity efforts. Microsoft is probing whether a leak from its confidential early warning system enabled Chinese state-sponsored hackers to exploit significant flaws in its SharePoint software, leading to breaches at over 400 organizations, including the U.S. agency responsible for…
-
Microsoft untersucht, ob SharePoint 0-day vorab an Hacker geleakt wurde
Konnten mutmaßlich chinesische Hacker vorab auf interne Beschreibungen von 0-Day-Schwachstellen in Microsoft SharePoint Server zugreifen, bevor diese am vorigen Wochenende ausgenutzt wurden? Microsoft untersucht jedenfalls, ob es ein Leak in internen Systemen gab, wo solche Informationen gespeichert sind. Angriff auf … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/26/microsoft-untersucht-ob-sharepoint-0-day-vorab-an-hacker-geleakt-wurde/
-
Microsoft-owned GitHub: Open source needs funding. Ya think?
‘Industry, national governments, and the EU’ must pay for maintainers. El Reg says charity shouldn’t start at home First seen on theregister.com Jump to article: www.theregister.com/2025/07/24/microsoftowned_github_says_open_source/
-
50 years ago, Gates and Allen made the deal that launched Microsoft
Tags: microsoftHow the MITS Altair 8800, a $264 RAM board, and some BASIC changed the world First seen on theregister.com Jump to article: www.theregister.com/2025/07/24/50y_of_gates_allen_mits_basic/
-
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft is investigating an ongoing outage blocking Microsoft 365 administrators with business or enterprise subscriptions from accessing the admin center. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-investigates-outage-affecting-microsoft-365-admin-center/
-
Microsoft admits it ‘cannot guarantee’ data sovereignty
Under oath in French Senate, exec says it would be compelled however unlikely to pass local customer info to US admin First seen on theregister.com Jump to article: www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/
-
Klage gegen IT-Helpdesk: Hacker sollen einfach nach Passwort gefragt haben
Auch bei der Umgehung der Zweifaktor-Authentifizierung Microsofts soll der IT-Helpdesk geholfen haben. First seen on golem.de Jump to article: www.golem.de/news/klage-gegen-it-helpdesk-hacker-sollen-einfach-nach-passwort-gefragt-haben-2507-198513.html
-
Klage gegen IT-Helpdesk: Hacker sollen einfach nach Passwort gefragt haben
Auch bei der Umgehung der Zweifaktor-Authentifizierung Microsofts soll der IT-Helpdesk geholfen haben. First seen on golem.de Jump to article: www.golem.de/news/klage-gegen-it-helpdesk-hacker-sollen-einfach-nach-passwort-gefragt-haben-2507-198513.html
-
Brave-Browser blockiert Microsoft Recall auf Tabs
Die Entwickler des Brave-Browsers haben zum 22. Juli 2025 angekündigt, dass sie ab der neuen Version 1.81 die Microsoft Recall-Funktion auf allen Tabs standardmäßig blockieren. Dies soll verhindern, dass Informationen auf den geöffneten Tabs an Microsofts sehr umstrittene Windows AI-Funktion … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/25/brave-browser-blockiert-microsoft-recall-auf-tabs/
-
Microsoft lifts Windows 11 update block for Easy Anti-Cheat users
Microsoft has removed a compatibility hold that prevented some Easy Anti-Cheat users from installing the Windows 11 2024 Update because of a known issue that triggers restarts with blue screen of death (BSOD) errors. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-lifts-windows-11-update-block-for-easy-anti-cheat-users/
-
Multiple Hacker Groups Exploit SharePoint 0-Day Vulnerability in the Wild
Tags: cve, cyber, cybercrime, exploit, flaw, group, hacker, microsoft, remote-code-execution, threat, vulnerability, zero-dayMicrosoft has confirmed that a pair of zero-day vulnerabilities in on-premises SharePoint Server, collectively dubbed ToolShell, are under active exploitation by diverse threat actors ranging from opportunistic cybercriminals to sophisticated nation-state advanced persistent threat (APT) groups. ToolShell encompasses CVE-2025-53770, a critical remote code execution (RCE) flaw allowing unauthenticated attackers to execute arbitrary code on vulnerable…
-
Experten warnen: Kritische Sicherheitslücke in Microsoft Sharepoint gefährdet tausende Server
First seen on t3n.de Jump to article: t3n.de/news/microsoft-sharepoint-experten-warnen-1698070/
-
Sharepoint Server 0-Day-Schwachstelle: über 400 Opfer, WarlockInfektionen
Langsam wird das Ausmaß der beobachteten Angriffswelle auf 0-Day-Schwachstellen in Microsoft SharePoint sichtbar. Microsoft hat inzwischen zwar Notfall-Updates für SharePoint Server freigegeben. Mittlerweile ist aber bekannt, dass über 400 Organisation wohl kompromittiert wurden. Und es steht fest, dass Angreifer die … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/25/sharepoint-server-0-day-schwachstelle-ueber-400-opfer-warlock-ransomware-infektionen/
-
Coyote malware is first-ever malware abusing Windows UI Automation
Tags: automation, banking, credentials, crypto, exploit, finance, framework, malware, microsoft, windowsNew Coyote malware uses Windows UI Automation to steal banking credentials, targeting Brazilian users across 75 banks and crypto platforms. Coyote malware is now the first to exploit Microsoft’s UI Automation framework in the wild, validating prior warnings from Akamai researchers in December 2024. The UI Automation (UIA) framework is a Microsoft accessibility framework that…
-
Datenkonflikt zwischen Europa und Amerika Vertreter bestätigt unter Eid Risiko für europäische Daten
First seen on security-insider.de Jump to article: www.security-insider.de/us-zugriff-europaeische-cloud-daten-microsoft-digitale-souveraenitaet-a-0e0d349084423354aa06e191f535cbe4/
-
Exchange 2016/2019 und Skype 2015/2019 bekommen 6 Monate ESU
Kurzer Nachtrag, der für Administratoren von Microsoft Exchange Server 2016/2019 sowie Microsoft Skye for Business 2015 bzw. 2019 interessant sein kann. Diese Software-Varianten sollten eigentlich zum 14. Oktober 2025 aus dem Support fallen. Wer noch nicht auf neuere Versionen umgestiegen … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/24/exchange-2016-2019-und-skype-2015-2019-bekommen-6-monate-esu/
-
U.S. CISA urges FCEB agencies to fix two Microsoft SharePoint flaws immediately and added them to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds two Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week, Microsoft warned of a SharePoint zero-day vulnerability, tracked as…

