Tag: microsoft
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
Windows-11-Update lässt Spiele und PCs abstürzen
Microsoft untersucht Probleme mit den August-Updates für Windows 11. Sowohl Videospiele als auch ganze PCs stürzen bei einigen Nutzern ab. First seen on golem.de Jump to article: www.golem.de/news/microsoft-windows-11-update-laesst-spiele-und-pcs-abstuerzen-2608-212113.html
-
Microsoft Defender Update Crashes Virus Scans on Windows PCs
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released on August 18, 2026. This issue has affected both consumer devices and Microsoft Defender for Endpoint-managed environments, disrupting a critical malware-detection capability for administrators and home users alike. Microsoft Defender Update Crashes Virus…
-
Microsoft says August Windows updates may cause gaming issues
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-may-cause-gaming-issues-reboots/
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
Microsoft removes WMIC tool from Windows 11
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-removes-wmic-tool-from-windows-11
-
‘TWINLOOT’ Python implant abuses Microsoft services for stealthy C2
First seen on scworld.com Jump to article: www.scworld.com/news/twinloot-python-implant-abuses-microsoft-services-for-stealthy-c2
-
Microsoft Links More Than 30 Domains to MacSync Stealer
Microsoft linked more than 30 rotating domains to MacSync Stealer by correlating endpoint and network behavior across the malware’s attack chain. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-macsync-stealer-30-domains/
-
Microsoft Copilot gehackt: KI verrät Forschern ihren eigenen Angriffsweg
Microsoft Copilot gehackt: Forscher bringen KI dazu, ihren eigenen Angriffsweg zu verraten. CoSnitch konnte Daten per One-Click abgreifen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/microsoft-copilot-gehackt-332791.html
-
CISA Warns Microsoft Internet Key Exchange RCE Flaw Is Actively Exploited
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, Internet, kev, microsoft, rce, remote-code-execution, service, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, tracked as CVE-2026-33824, is currently being actively exploited. The issue is classified as a double-free vulnerability, which means it affects the memory management of Microsoft…

