Tag: microsoft
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
M365 als Angriffsinfrastruktur – Phishing nutzt echte Microsoft-Anmeldeseiten aus
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-nutzt-echte-microsoft-anmeldeseiten-aus-a-d623eeb22614be43cbe10944e6643c75/
-
China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure. Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
-
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.The use of StormEncryptor marks a shift from the adversary’s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.”StormEncryptor is written in C++ and appends the file name extension .encrypted First seen…
-
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/secure-development-ai-cyber-vulnerabilities-Black-Hat/827435/
-
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
Tags: china, cybersecurity, exploit, hacker, microsoft, ransomware, software, threat, tool, vulnerabilityA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. First seen on therecord.media Jump to article: therecord.media/china-hackers-ransomware-microsoft
-
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/
-
Absicherung der digitalen Belegschaft
“‹Vor kurzem hat Nvidia gemeinsam mit Microsoft, Cisco, Crowdstrike, Palo Alto Networks und vielen weiteren Unternehmen die <> gegründet. Hinter dieses Bündnis stellt sich auch KnowBe4. Ziel der Allianz ist, offene Werkzeuge zu entwickeln und bereitzustellen, mit denen sich KI im Zeitalter autonomer Agenten absichern lässt. Warum KnowBe4 die Open-Secure-AI-Alliance unterstützt, erläutert […] First seen…
-
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExec, illustrates how attackers can turn routine Windows administration into cover for lateral movement and payload execution. The binary has been observed alongside…
-
Pwnie Award: Microsoft gewinnt Schampreis für angedrohte Strafverfolgung
Tags: microsoftMicrosoft hat durch seinen Streit mit Chaotic Eclipse einen Pwnie Award gewonnen. Annehmen wollte ihn wohl keiner – aus Angst vor Jobverlust. First seen on golem.de Jump to article: www.golem.de/news/pwnie-award-microsoft-gewinnt-schampreis-fuer-angedrohte-strafverfolgung-2608-211753.html
-
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer.The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-proAlthough neither of the extensions is now available on Open VSX, the GitHub repository First seen on thehackernews.com Jump…
-
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The activity closely overlaps with Microsoft’s “Payroll Pirates” cluster, tracked as Storm-2755. Researchers also found similarities with activity previously documented by Security Risk Advisors, indicating that…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026. The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling. The group was previously associated with…
-
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/
-
Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello…
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.”The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, First seen on thehackernews.com…
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/07/august-2026-patch-tuesday-forecast/
-
Swiss government SharePoint breach compromised 200 accounts
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
-
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/microsoft-zero-trust-for-ai-strategy-updates/
-
Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt
Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert. First seen on golem.de Jump to article: www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommunikation-ueber-sharepoint-gehackt-2608-211659.html
-
Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges
Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-bug-bounty-payouts-20-million/
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…
-
TENEX.ai Launches Turn-Key Agentic SecOps Platform, Deployable in a Week
TENEX.ai announced commercial availability of a turn-key, fully agentic, human-led Security Operations platform at Black Hat 2026, positioning it as a new category the company calls >>Fully-Agentic, Human-Led Security Operations.<< The platform deploys on Google SecOps or Microsoft Sentinel and can go operational in as little as seven days, without replacing existing security infrastructure, deploying..…
-
Hacker greifen 120 Unternehmen über offizielle Microsoft-Dienste mit Phishing-Mails an
Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies hat eine neue Phishing-Taktik von Angreifern aufgedeckt und analysiert, die sich Microsofts Infrastruktur zunutze macht und deren Vertrauenswürdigkeit ausnutzt. Vom 25. Juni bis in die zweite Juliwoche identifizierte CPR mehr als 200 Phishing-E-Mails, die sich an Nutzer in rund 120 Organisationen richteten und dabei…
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Angriff gegen 120 Unternehmen Kampagne nutzt echte Microsoft-Anmeldung
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-microsoft-teams-echte-login-seite-boesartige-app-berechtigungen-a-2fa1636d91b31c8388f4555881a3fc9f/
-
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries, highlighting the global nature of coordinated vulnerability disclosure efforts that help protect Microsoft customers worldwide. This represents significant growth over…

