Tag: microsoft
-
Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap
A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled. The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-azure-cli-mfa-gap/
-
Sicherheitsdienst speziell für KI-Agenten in Microsoft-Umgebungen
Bluevoyant gibt die Einführung seines ‘Microsoft Agent 365 Security Deployment Service” bekannt, des ersten professionellen Dienstleistungsprogramms, das Unternehmen dabei unterstützt, die in ihrer Microsoft-Umgebung ausgeführten KI-Agenten zu identifizieren, zu verwalten und abzusichern. Die Einführung des Dienstes erfolgt zu einem Zeitpunkt, zu dem Unternehmen weltweit darum wetteifern, möglichst rasch KI-Agenten einzuführen schneller als ihre Sicherheitsteams […]…
-
Hackers Use Trusted Microsoft Domain and One-Time Codes to Hijack Corporate Accounts
A rising phishing technique is exploiting a legitimate Microsoft authentication flow to hijack corporate accounts without stealing passwords. Attackers are weaponizing the OAuth 2.0 Device Authorization Grant commonly used to sign in input-constrained devices via a one-time user code to trick victims into approving access on Microsoft’s own domain. Because the final authentication occurs on…
-
Microsoft Warns Windows 11 Enterprise Devices May Boot to Black Screen After Updates
Microsoft has issued a warning to enterprise administrators about a critical issue affecting Windows 11 systems. This problem may cause devices to boot to a black screen or experience severe shell failures following recent cumulative updates. The issue, documented under KB5072911, affects Windows 11 versions 24H2 and 25H2 when updates released on or after July…
-
BlueVoyant startet Sicherheitsdienst für KI-Agenten in Microsoft-Umgebungen
BlueVoyant stellt den Microsoft Agent 365 Security Deployment Service vor. Der Dienst soll KI-Agenten in Microsoft-Umgebungen sichtbar, steuerbar und sicherer machen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/bluevoyant-startet-sicherheitsdienst-fuer-ki-agenten-in-microsoft-umgebungen/a45674/
-
Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts
A Mac-targeting ClickFix campaign amplified through a verified X sponsored ad, and a novel browser-based hijack technique called ConsentFix that exfiltrates Microsoft 365 session tokens without traditional malware. Researchers at Jamf and Malwarebytes tracked the X incident where a verified account ran a sponsored advertisement promoting a macOS utility dubbed “DynamicLake” a lookalike for legitimate…
-
ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit
A new phishing-as-a-service (PhaaS) platform dubbed “ARToken” appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/
-
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows authenticated low-privileged users to access and read arbitrary files from vulnerable Exchange servers. The vulnerability, discovered by security researcher Batuhan Er from HawkTrace, affects Microsoft Exchange Server 2019. Microsoft Exchange SSRF…
-
Behörde warnt: Microsoft-Sharepoint-Server werden attackiert
Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln. First seen on golem.de Jump to article: www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden-attackiert-2607-210462.html
-
US cyber agency warns over forgotten SharePoint flaw
An RCE vulnerability in Microsoft SharePoint that was mistakenly omitted from the May Patch Tuesday bulletin is being exploited in the wild, says Cisa. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645307/US-cyber-agency-warns-over-forgotten-SharePoint-flaw
-
Angriffe auf Azure-CLI: Millionen Passwort-Angriffe auf Microsoft-Konten
Ein massiver Password-Spray-Angriff auf das Azure-CLI kompromittierte 78 Microsoft-Konten. Angreifer nutzten ein veraltetes OAuth-Verfahren als Bypass. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/angriffe-auf-azure-cli
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…
-
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/
-
Microsoft fixes bug that removed Copilot buttons in Outlook
Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-removed-copilot-button-in-outlook/
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
CISA Adds Actively Exploited Microsoft SharePoint Vulnerability to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a newly discovered vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition highlights the active exploitation risks present in enterprise environments. The vulnerability falls under the CWE-502 (Deserialization of Untrusted Data) category, allowing an authenticated attacker to…
-
Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-perplexity-chrome-extension-searches/
-
Microsoft SharePoint RCE flaw now actively exploited
CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
-
81 Millionen Anmeldeversuche: Massenangriff auf Microsoft-Konten
Tags: microsoftForscher warnen vor einer neuen Angriffswelle auf Microsoft-365-Konten. Die Angreifer testen massenhaft Zugangsdaten durch, teilweise mit Erfolg. First seen on golem.de Jump to article: www.golem.de/news/81-millionen-anmeldeversuche-massenangriff-auf-microsoft-konten-2607-210424.html
-
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue First seen…
-
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June 12 and June 26, 2026. According to researchers from Huntress, the activity primarily originates from…
-
Cordyceps gefährdet CI/CD-Pipelines auf GitHub – Cordyceps trifft Repositories von Microsoft, Google und anderen
First seen on security-insider.de Jump to article: www.security-insider.de/cordyceps-github-cicd-pipeline-microsoft-google-schwachstelle-a-5937c5d6b9fbe3379be3997686acb4a6/
-
Quantum Breakthroughs Compress Post-Quantum Computing Timeline
Microsoft, Google and AWS cite major gains in reliability and error correction.. Rapid advances in quantum hardware, AI-assisted error correction and fault-tolerant architectures from Microsoft, Google and Amazon are accelerating expectations for practical quantum computing, increasing pressure on organizations to adopt crypto-agility and prepare for post-quantum encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quantum-breakthroughs-compress-post-quantum-computing-timeline-a-32137
-
Phishing Tactics Target Session Tokens and Deliver Malware
Barracuda found phishing attacks increasingly abuse Microsoft authentication, session tokens, and fileless malware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/phishing-tactics-target-session-tokens-and-deliver-malware/
-
Cisco Talos Exposes ARToken Microsoft 365 Phishing Kit
Cisco Talos uncovered ARToken, a Microsoft 365 phishing platform built for persistent access and BEC attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cisco-talos-exposes-artoken-microsoft-365-phishing-kit/
-
Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan
Microsoft and Trend Micro found hotel phishing attacks using fake guest complaints and photo links to target staff in Japan. The post Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-hotel-phishing-apac-japan/
-
Azure Password-Spraying Attack Bypasses MFA Defenses
Threat Actor Uses Deprecated OAuth 2.0 Authentication Flow. Attackers behind a password-spraying campaign targeting Microsoft Office 365 accounts have amassed dozens of victims by abusing a deprecated feature in OAuth 2.0 to generate access tokens, in some cases sidestepping multifactor authentication controls, warn researchers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/azure-password-spraying-attack-bypasses-mfa-defenses-a-32128
-
Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users. First seen on hackread.com Jump to article: hackread.com/fake-google-notes-browser-extension-swap-crypto-wallets/
-
Hackers target Microsoft 365 accounts with 81 million login attempts
An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/

