Tag: microsoft
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
The Best Agentic SOC for Microsoft Sentinel in 2026 (and Where Security Copilot Fits)
The 8 best agentic SOC platforms for Microsoft Sentinel in 2026, compared. What Security Copilot’s agents do today, GA versus preview, and where the gap is. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-best-agentic-soc-for-microsoft-sentinel-in-2026-and-where-security-copilot-fits/
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Microsoft warnt: Russische Hacker verbreiten Malware über öffentliche WLANs
Die Angreifer haben wohl WLAN-Netze von Hotels, Flughäfen und anderen Einrichtungen infiltriert, um Daten abzugreifen und Malware zu verbreiten. First seen on golem.de Jump to article: www.golem.de/news/microsoft-warnt-russische-hacker-verbreiten-malware-ueber-oeffentliche-wlans-2608-211540.html
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/
-
Security Affairs newsletter Round 588 by Pierluigi Paganini INTERNATIONAL EDITION
Tags: adobe, email, flaw, hacker, international, microsoft, russia, vulnerability, WeeklyReview, wifiA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight…
-
ShinyHunters Claims Brinks Home Salesforce Data Theft
ShinyHunters claims it breached Brinks Home through a Microsoft Entra vishing attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/shinyhunters-claims-brinks-home-salesforce-data-theft/
-
The Security Interviews: Nicole Darden Ford, Microsoft
As a black woman in the white, male-dominated world of cyber security, Microsoft’s Nicole Darden Ford has worked hard to carve out her space in the room. She talks about developing confidence and self-belief, building community, and leading with humility First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646265/The-Security-Interviews-Nicole-Darden-Ford-Microsoft
-
Vishing-Kampagne über Microsoft Teams mündet in Chaos-Ransomware
Angreifer geben sich über Microsoft Teams als IT-Support aus, um sich Fernzugriff auf Firmengeräte zu verschaffen. Darauf folgte der Einsatz der Ransomware Chaos. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-teams-chaos
-
Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken
Tags: microsoftMit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können – auch die von Microsoft. First seen on golem.de Jump to article: www.golem.de/news/microsoft-forscher-finden-masterkey-fuer-vollzugriff-auf-azure-datenbanken-2607-211473.html
-
Top 10 Companies to Hire Power BI Developers in 2026
Compare 10 Power BI development companies for 2026, covering DAX, Microsoft Fabric, data engineering, security, compliance, AI, and enterprise BI project needs. First seen on hackread.com Jump to article: hackread.com/top-companies-hire-power-bi-developers-in-2026/
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies, like Microsoft and now Google, are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
-
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates
-
Microsoft launches agentic security platform designed to combat AI-based attacks
The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-agentic-security-platform-ai-attacks/826365/
-
Satya Nadella empfiehlt: Unternehmen sollen Kontrolle über ihre Daten behalten
Unternehmen, die sich beim Training von KI-Modellen allein auf deren Anbieter verlassen, werden laut dem Microsoft-CEO nicht überleben. First seen on golem.de Jump to article: www.golem.de/news/satya-nadella-empfiehlt-unternehmen-sollen-kontrolle-ueber-ihre-daten-behalten-2607-211366.html
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…
-
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/
-
Open Secure AI Alliance: Warum Microsoft, OpenAI und Nvidia plötzlich auf Open-Source-KI setzen
Trotz der durchaus sinnvollen Forderungen der Tech-Konzerne zur Abwehr von KI-Gefahren drängen sich auch andere Motive auf. First seen on golem.de Jump to article: www.golem.de/news/open-secure-ai-alliance-warum-microsoft-openai-und-nvidia-ploetzlich-auf-open-source-ki-setzen-2607-211359.html
-
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations First seen on hackread.com Jump to article: hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
OpenAI steigt erstmals in Top 10 der imitierten Marken auf
Check Point zeigt im Q2-2026-Bericht: Microsoft führt das Phishing-Ranking an, während ChatGPT von OpenAI erstmals unter den zehn meistimitierten Marken liegt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/openai-top-10-der-imitierten-marken
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…

