Tag: microsoft
-
Microsoft sperrt Virenscanner vom Kernelzugriff aus eine Mogelpackung?
Ende Juni 2025 gab es Meldungen (habe ich jedenfalls so interpretiert), dass Virenscanner in “Bälde” nicht mehr den Kernelmode von Windows verwenden dürfen. Der CrowdStrike-Fall, der Millionen Windows-Systeme lahm legte, war laut Microsoft die endgültige Warnung, den Schritt einzuleiten. Die … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/03/microsoft-sperrt-virenscanner-vom-kernelzugriff-aus-ein-mogelpackung/
-
Microsoft Copilot joins ChatGPT at the feet of the mighty Atari 2600 Video Chess
Copilot’s confidence was… misplaced First seen on theregister.com Jump to article: www.theregister.com/2025/07/01/microsoft_copilot_joins_chatgpt_at/
-
Microsoft sperrt Virenscanner vom Kernelzugriff aus ein Mogelpackung?
Ende Juni 2025 gab es Meldungen (habe ich jedenfalls so interpretiert), dass Virenscanner in “Bälde” nicht mehr den Kernelmode von Windows verwenden dürfen. Der CrowdStrike-Fall, der Millionen Windows-Systeme lahm legte, war laut Microsoft die endgültige Warnung, den Schritt einzuleiten. Die … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/03/microsoft-sperrt-virenscanner-vom-kernelzugriff-aus-ein-mogelpackung/
-
Microsoft fixes ‘Print to PDF’ feature broken by Windows update
Microsoft has fixed a known bug that breaks the ‘Print to PDF’ feature on Windows 11 24H2 systems after installing the April 2025 preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-print-to-pdf-feature-broken-by-windows-update/
-
Cybercriminals Use Malicious PDFs to Impersonate Microsoft, DocuSign, and Dropbox in Targeted Phishing Attacks
Cisco’s Talos security team has uncovered a surge in sophisticated phishing campaigns leveraging malicious PDF payloads to impersonate trusted brands like Microsoft, DocuSign, and Dropbox. According to a recent update to Cisco’s brand impersonation detection engine, these attacks have expanded in scope, targeting a broader array of well-known organizations with deceptive emails designed to exploit…
-
Auf der Suche nach Alternativen zum CVE-Programm
Tags: advisory, ceo, cisa, cve, cvss, cyber, cyersecurity, exploit, github, google, group, infrastructure, intelligence, kev, microsoft, nist, nvd, open-source, oracle, ransomware, resilience, risk, siem, soar, software, supply-chain, threat, tool, update, vulnerability, vulnerability-management, zero-daySollte das CVE-Programm eingestellt werden, wäre die Bewertung und Behebung von Sicherheitslücken schwieriger.Der jüngste kurze Panikausbruch wegen der möglichen Einstellung des Common Vulnerabilities and Exposures (CVE)-Programms hat die starke Abhängigkeit der Sicherheitsbranche von diesem Programm deutlich gemacht. Er führte zu Diskussionen über Notfallstrategien , falls das standardisierte System zur Identifizierung und Katalogisierung von Schwachstellen nicht…
-
Critics blast Microsoft’s limited reprieve for those stuck on Windows 10
Users tired of being ‘yanked around’ as end of support looms First seen on theregister.com Jump to article: www.theregister.com/2025/07/01/windows_10_updates_criticism/
-
DNS issue blocks delivery of Exchange Online OTP codes
Microsoft is working to fix a DNS misconfiguration that is causing one-time passcode (OTP) message delivery failures in Exchange Online for some users. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-links-dns-issue-to-exchange-online-otp-delivery-failures/
-
Office”¯365 Introduces New Mail Bombing Detection to Shield Users
Microsoft has announced a significant security upgrade for its Office 365 platform, introducing a new Mail Bombing Detection feature within Microsoft Defender for Office 365. This enhancement, rolling out globally from late June through early July 2025, is designed to automatically identify and block email bombing attacks”, a growing threat that floods user inboxes with…
-
Microsoft Ends Authenticator App’s Password Management Support From 2025
Microsoft has announced it will discontinue password management features in its widely used Authenticator app, marking a significant shift in its approach to digital security. Starting July 2025, the app’s autofill capability will be disabled, and by August 2025, all saved passwords will be permanently removed from the app. A Strategic Move Toward Passwordless Security…
-
DCRat Targets Windows Systems for Remote Control, Keylogging, Screen Capture, and Data Theft
A sophisticated email-based attack distributing a Remote Access Trojan (RAT) known as DCRat has been recently identified by the FortiMail IR team, specifically targeting organizations in Colombia. The campaign, impersonating a Colombian government entity, leverages advanced evasion techniques to compromise Microsoft Windows systems. With a high severity level, this threat aims to control infected devices…
-
Microsoft Intune Update Wipes Custom Security Baseline Tweaks Admins Alerted
Microsoft has confirmed a significant issue affecting its Intune security baseline update process, causing concern among IT administrators worldwide. The problem, acknowledged by Microsoft in late June, results in custom security baseline configurations being lost when updating to a newer baseline version, such as moving from one annual update to another. This flaw has left…
-
Scope, Scale of Spurious North Korean IT Workers Emerges
Microsoft warns thousands of North Korean workers have infiltrated tech, manufacturing, and transportation sectors to steal money and data. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/scope-scale-spurious-north-korean-it-workers
-
How Microsoft plans to improve resiliency 1 year after CrowdStrike outage
First seen on scworld.com Jump to article: www.scworld.com/news/how-microsoft-plans-to-improve-resiliency-1-year-after-crowdstrike-outage
-
Microsoft admits to Intune forgetfulness
Customizations not saved with security baseline policy update First seen on theregister.com Jump to article: www.theregister.com/2025/07/01/microsoft_intune_forgetfulness/
-
Microsoft open-sources VS Code Copilot Chat extension on GitHub
Microsoft has released the source code for the GitHub Copilot Chat extension for VS Code under the MIT license. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-open-sources-vs-code-copilot-chat-extension-on-github/
-
Microsoft introduces protection against email bombing
By the end of July 2025, all Microsoft Defender for Office 365 customers should be protected from email bombing attacks by default, Microsoft has announced on Monday. What is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/07/01/microsoft-introduces-protection-against-email-bombing/
-
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status
A new study of integrated development environments (IDEs) like Microsoft Visual Studio Code, Visual Studio, IntelliJ IDEA, and Cursor has revealed weaknesses in how they handle the extension verification process, ultimately enabling attackers to execute malicious code on developer machines.”We discovered that flawed verification checks in Visual Studio Code allow publishers to add functionality First…
-
Scammers Use Microsoft 365 Direct Send to Spoof Emails Targeting US Firms
Scammers are exploiting Microsoft 365 Direct Send to spoof internal emails targeting US firms bypassing security filters with… First seen on hackread.com Jump to article: hackread.com/scammers-microsoft-365-direct-spoof-emails-us-firms/
-
Microsoft Teams Enables In”‘Chat Bot Agent Integration
Microsoft Teams is set to revolutionize workplace collaboration once again, rolling out a highly anticipated feature that enables users to add bots and agents directly within Chats and Channels, without disrupting their ongoing conversations. The update, announced under Message ID MC1093236, marks a significant step towards a more fluid and productive Teams experience. Starting in…
-
OneClik Red Team Campaign Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors
Cybersecurity researchers have detailed a new campaign dubbed OneClik that leverages Microsoft’s ClickOnce software deployment technology and bespoke Golang backdoors to compromise organizations within the energy, oil, and gas sectors.”The campaign exhibits characteristics aligned with Chinese-affiliated threat actors, though attribution remains cautious,” Trellix researchers Nico Paulo First seen on thehackernews.com Jump to article: thehackernews.com/2025/06/oneclik-malware-targets-energy-sector.html
-
North Korean IT Workers Employ New Tactics to Infiltrate Global Organizations
Tags: ai, china, cyber, intelligence, korea, microsoft, north-korea, russia, tactics, technology, threat, toolMicrosoft Threat Intelligence has uncovered a sophisticated operation by North Korean remote IT workers who are leveraging cutting-edge artificial intelligence (AI) tools to infiltrate organizations worldwide. Since at least 2020, these highly skilled individuals, often based in North Korea, China, and Russia, have been targeting technology-related roles across various industries to generate revenue for the…
-
US DoJ and Microsoft Target North Korean IT Workers
Both the US authorities and Microsoft have taken action to disrupt North Korean IT worker schemes First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/us-doj-microsoft-target-north/
-
Wirbel um Microsoft-Zahlen Update – – Windows verliert keine 400 Millionen Nutzer in drei Jahren
Microsoft-Zahlen erweckten den Eindruck, dass Windows in drei Jahren 400 Millionen Nutzer verloren hat. Der Konzern hat sich korrigiert. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/von-1-4-mrd-auf-1-mrd-geraete-windows-verlor-in-3-jahren-rund-400-millionen-nutzer.93338
-
Microsoft Removes Password Management from Authenticator App Starting August 2025
Microsoft has said that it’s ending support for passwords in its Authenticator app starting August 1, 2025.The changes, the company said, are part of its efforts to streamline autofill in the two-factor authentication (2FA) app.”Starting July 2025, the autofill feature in Authenticator will stop working, and from August 2025, passwords will no longer be accessible…
-
PowerShell überwachen so geht’s
Tags: access, cloud, cyberattack, detection, hacker, login, mail, microsoft, monitoring, powershell, tool, windowsWird PowerShell nicht richtig überwacht, ist das Security-Debakel meist nicht weit.Kriminelle Hacker setzen mitunter auf raffinierte Techniken, um sich über ausgedehnte Zeiträume in den Netzwerken von Unternehmen einzunisten und still und heimlich sensible Daten oder Logins abzugreifen. Dabei missbrauchen die Cyberkriminellen in vielen Fällen auch vom jeweiligen Zielunternehmen freigegebene Tools, um sich initial Zugang zu…
-
Microsoft’s next Windows 11 update is more ‘enablement’ than upgrade
If you didn’t like 24H2, you’re probably not going to like 25H2 First seen on theregister.com Jump to article: www.theregister.com/2025/06/30/microsoft_windows_11_25h2/

