Tag: microsoft
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies, like Microsoft and now Google, are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
-
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates
-
Microsoft launches agentic security platform designed to combat AI-based attacks
The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-agentic-security-platform-ai-attacks/826365/
-
Satya Nadella empfiehlt: Unternehmen sollen Kontrolle über ihre Daten behalten
Unternehmen, die sich beim Training von KI-Modellen allein auf deren Anbieter verlassen, werden laut dem Microsoft-CEO nicht überleben. First seen on golem.de Jump to article: www.golem.de/news/satya-nadella-empfiehlt-unternehmen-sollen-kontrolle-ueber-ihre-daten-behalten-2607-211366.html
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…
-
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/
-
Open Secure AI Alliance: Warum Microsoft, OpenAI und Nvidia plötzlich auf Open-Source-KI setzen
Trotz der durchaus sinnvollen Forderungen der Tech-Konzerne zur Abwehr von KI-Gefahren drängen sich auch andere Motive auf. First seen on golem.de Jump to article: www.golem.de/news/open-secure-ai-alliance-warum-microsoft-openai-und-nvidia-ploetzlich-auf-open-source-ki-setzen-2607-211359.html
-
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations First seen on hackread.com Jump to article: hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
OpenAI steigt erstmals in Top 10 der imitierten Marken auf
Check Point zeigt im Q2-2026-Bericht: Microsoft führt das Phishing-Ranking an, während ChatGPT von OpenAI erstmals unter den zehn meistimitierten Marken liegt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/openai-top-10-der-imitierten-marken
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed
A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a “secure document” lure. Victims are redirected through compromised infrastructur to a…
-
Microsoft debuts AI cybersecurity offerings as competition heats up
It includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-ai-cybersecurity-project-perception/
-
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/microsoft-unveils-ai-security-tools-it-says-outperform-competing-platforms/
-
Microsoft Unveils AI Security Stack, Low-Cost Cyber Model
Project Perception Combines AI Agents With New MAI-Cyber-1-Flash Model. Microsoft introduced Project Perception, an AI-powered security platform that coordinates specialized agents to detect, investigate and remediate cyberthreats. The company also launched MAI-Cyber-1-Flash, a cybersecurity model it says outperforms competing models while costing roughly half as much. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/microsoft-unveils-ai-security-stack-low-cost-cyber-model-a-32343
-
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates. First seen on hackread.com Jump to article: hackread.com/microsoft-certighost-flaw-domain-controller-impersonation/
-
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
Microsoft unveils MAI1-Flash, promises cybersecurity AI at half the cost
Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/microsoft-mai-cyber-1-flash-ai-model/
-
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/27/microsoft-launches-its-first-cyber-model-and-a-new-agentic-cybersecurity-system/
-
OpenAI erstmals unter den zehn meistimitierten Marken
Der Bericht von Check Point über das Brand-Phishing-Ranking für das zweite Quartal 2026 listet erstmals eines der großen KI-Unternehmen in den Top 10. Die Experten beobachteten zudem konkrete Betrugsmaschen mit ChatGPT, Paypal, iCloud und Microsoft Microsoft bleibt weiterhin Spitzenreiter als meistimitierte Marke und vereint 23 Prozent aller Brand-Phishing-Versuche im Quartal auf sich. Das sind fast…
-
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens. First seen on hackread.com Jump to article: hackread.com/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts/
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools.”The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in First…
-
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/check-point-brand-phishing-trends-report/
-
Check Point Brand Phishing Ranking: Microsoft bleibt vorn, ChatGPT erstmals in den Top 10
ChatGPT erreicht erstmals die Top 10 der meistimitierten Marken. Microsoft bleibt laut Check Point mit 23 Prozent das wichtigste Phishing-Ziel. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-brand-phishing-ranking-microsoft-bleibt-vorn-chatgpt-erstmals-in-den-top-10/a45875/
-
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.”The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,” the Microsoft-owned subsidiary said.According…

