Tag: microsoft
-
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-sharepoint-attack-new-exploit/825797/
-
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-esu-program-ends-in-october/
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities,…
-
Xbox: Microsoft will Support für gehackte Konten verbessern
Laut einem Bericht arbeitet Microsoft an besseren Prozessen für gehackte Konten. Bislang konnten Betroffene dauerhaft den Zugriff verlieren. First seen on golem.de Jump to article: www.golem.de/news/xbox-microsoft-will-support-fuer-gehackte-konten-verbessern-2607-211149.html
-
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal…
-
Zwei Drittel der Unternehmen verschieben die Einführung von Microsoft Copilot wegen Datenschutzrisiken
Zwei von drei (66 %) Unternehmen haben Bedenken, dass Microsoft Copilot vertrauliche Daten offenlegen könnte und haben deshalb die Einführung des KI-Assistenten verschoben oder komplett gestrichen. Zudem befürchten nahezu drei Viertel (73 %) der Benutzer, dass KI bereits intern sensible Informationen preisgibt. Zu diesen und weiteren Ergebnissen kommt der neue Report »State of Microsoft… First…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools returns…
-
HollowGraph malware uses Microsoft 365 calendar for command and control
First seen on scworld.com Jump to article: www.scworld.com/brief/hollowgraph-malware-uses-microsoft-365-calendar-for-command-and-control
-
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization…
-
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
-
Künstliche Intelligenz: Microsoft und Mistral arbeiten bei KI in Europa zusammen
Microsoft und Mistral arbeiten künftig zusammen. Mistrals KI-Modelle sind ab sofort in Microsofts Entwicklungsplattformen und in Copilot Studio verfügbar. First seen on golem.de Jump to article: www.golem.de/news/kuenstliche-intelligenz-microsoft-und-mistral-abreiten-bei-ki-in-europa-zusammen-2607-211119.html
-
Zwei Drittel der Unternehmen verschieben die Einführung von Microsoft-Copilot wegen Datenschutzrisiken
Zwei von drei (66 %) Unternehmen haben Bedenken, dass Microsoft-Copilot vertrauliche Daten offenlegen könnte und haben deshalb die Einführung des KI-Assistenten verschoben oder komplett gestrichen. Zudem befürchten nahezu drei Viertel (73 %) der Benutzer, dass KI bereits intern sensible Informationen preisgibt. Zu diesen und weiteren Ergebnissen kommt der neue Report ‘State of Microsoft 365 Security…
-
Microsoft und Mistral erweitern Partnerschaft für souveräne KI
Microsoft und Mistral haben eine neue, mehrjährige Vereinbarung im Umfang von mehreren Milliarden Dollar geschlossen. Im Mittelpunkt stehen zusätzliche KI-Rechenkapazitäten für Microsoft in Europa, die Integration aktueller Mistral-Modelle in Microsofts KI-Plattformen sowie neue Möglichkeiten für Unternehmen und regulierte Branchen, führende KI-Anwendungen in unterschiedlichen Betriebsumgebungen umzusetzen. Die Vereinbarung soll Unternehmen mehr Wahlfreiheit und Kontrolle geben: Sie…
-
New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as…
-
Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises…
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeouts/
-
Windows 11 24H2 und 25H2 – Release Preview bringt Voice Isolation und neue Touchpad-Funktionen
Microsoft hat mit den Versionen 26100.8942 (24H2) und 26200.8942 (25H2) neue Release-Preview-Builds für Windows 11 veröffentlicht. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/windows-11-24h2-und-25h2-release-preview-bringt-voice-isolation-und-neue-touchpad-funktionen.98476
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
25 Jahre digitales Leben einfach weg: Was ein Hack mit deinem Microsoft-Konto anrichten kann
Tags: microsoftFirst seen on t3n.de Jump to article: t3n.de/news/streamer-verliert-microsoft-konto-hack-25-jahre-daten-1752992/
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
-
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
China-Support für Pentagon: Microsoft-Mittelsmänner vertrauten blind auf Codesicherheit
Neue Informationen zeigen im Detail, wie Microsoft getrickst hat, um für den IT-Support im Pentagon chinesische Ingenieure einsetzen zu können. First seen on golem.de Jump to article: www.golem.de/news/china-support-fuer-pentagon-microsoft-mittelsmaenner-vertrauten-blind-auf-codesicherheit-2607-211083.html
-
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
-
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed…
-
Microsoft confirms Windows Server Update Services sync delays
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
-
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/

