Tag: microsoft
-
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup
The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-365-fake-passkey-setup-enrollment/
-
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
-
Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/
-
SECARDEO certEntra v2 automatisiert S/MIME- und CBA-Zertifikate für Microsoft Entra ID
Tags: microsoftFür Unternehmen bedeutet das: Zertifikatsmanagement wird nicht nur zur Frage der heutigen IT-Sicherheit, sondern auch zur Vorbereitung auf kommende kryptografische Anforderungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/secardeo-certentra-v2-automatisiert-s-mime-und-cba-zertifikate-fuer-microsoft-entra-id/a45714/
-
SECARDEO certEntra v2 automatisiert S/MIME- und CBA-Zertifikate für Microsoft Entra ID
Tags: microsoftFür Unternehmen bedeutet das: Zertifikatsmanagement wird nicht nur zur Frage der heutigen IT-Sicherheit, sondern auch zur Vorbereitung auf kommende kryptografische Anforderungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/secardeo-certentra-v2-automatisiert-s-mime-und-cba-zertifikate-fuer-microsoft-entra-id/a45714/
-
Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection Engine used by Defender. The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal…
-
Microsoft to retire the OWA Light client in Exchange Server
Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-announces-owa-light-retirement-in-exchange-server/
-
‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies
Microsoft co-signed a malicious kernel driver, and now it’s being used to kill security software in ransomware attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
Update gegen Rogueplanet: Microsoft reagiert auf gefährlichen Defender-Exploit
Der Rogueplanet-Exploit verleiht Angreifern unter Windows weitreichende Systemrechte. Ein Update für den Microsoft Defender soll schützen. First seen on golem.de Jump to article: www.golem.de/news/update-gegen-rogueplanet-microsoft-reagiert-auf-gefaehrlichen-defender-exploit-2607-210674.html
-
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/
-
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
Attackers use Microsoft Teams voice calls to deliver EtherRAT malware
First seen on scworld.com Jump to article: www.scworld.com/brief/attackers-use-microsoft-teams-voice-calls-to-deliver-etherrat-malware
-
The Most Elusive Criminal Quality: Anonymity
Suspected Scattered Spider Member Reportedly Unmasked After Making Death Threat How did investigators unmask a 19-year-old suspected Scattered Spider extortionist? Amateur sleuths have highlighted Microsoft-gathered device telemetry in charging documents. But a researcher said he was quickly unmasked and tracked for years, after he sent her a death threat. First seen on govinfosecurity.com Jump to…
-
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.”The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the…
-
Windows 11 26H2 Enables Backup Policy to Restore User Apps and Settings
Microsoft has confirmed a significant policy change in the upcoming Windows 11 version 26H2. This update introduces a new default behavior for Windows settings backup, which could affect enterprise security baselines and device resilience strategies. According to an official announcement published on July 6, 2026, the Windows settings backup policy will change from being disabled…
-
UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories
More than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government’s Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-gov-launches-cyber-resilience/
-
M&S among first businesses to sign UK government’s resilience pledge
Marks & Spencer joins the likes of Accenture, Microsoft and Vodafone by committing to take practical steps to improve cyber standards through the government’s voluntary Cyber Resilience Pledge First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645538/MS-among-first-businesses-to-sign-UK-governments-resilience-pledge
-
Microsoft to enable Windows settings backup by default for orgs
Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-to-enable-windows-backup-for-organizations-by-default/
-
Microsoft Introduces Execution Containers to Secure AI Agents on Windows
Microsoft has introduced a new security architecture to safeguard autonomous AI agents on Windows, unveiling the Microsoft Execution Containers (MXC) SDK at Build 2026. The move reflects a growing industry concern: as AI agents evolve from passive assistants into autonomous systems capable of executing code, accessing files, and orchestrating workflows, they introduce significant security and…
-
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-testing-new-cloud-rebuild-windows-11-recovery-feature/
-
Microsoft wants to keep your AI agents from going rogue
Microsoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/microsoft-execution-containers-ai-agents-constraints/
-
Microsoft Edge High-Severity Vulnerability Allows Remote Code Execution
Microsoft has disclosed a high-severity remote code execution (RCE) vulnerability in its Chromium-based Edge browser, identified as CVE-2026-57992. This vulnerability could allow attackers to execute arbitrary code on affected systems under specific conditions. Publicly disclosed on July 3, 2026, it is classified as CWE-416 (Use-After-Free), which is a memory safety flaw. This issue occurs when…
-
Microsoft Teams allows users to turn off AI features
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-teams-allows-users-to-turn-off-ai-features
-
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/

