Tag: microsoft
-
Microsoft Defender vs Bitdefender: Compare Antivirus Software in 2026
Compare Microsoft Defender and Bitdefender across pricing, features, support, and business use cases in 2026 to find the best antivirus solution. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/microsoft-defender-vs-bitdefender/
-
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says.The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear.The lure…
-
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/mirage2fa-phishing-kit-microsoft-365-html-smuggling/
-
Doppelschlag auf SharePoint: Zwei Ransomware-Gruppen greifen zeitgleich an
Eine Untersuchung von Microsoft zeigt, dass zwei unterschiedliche Angreifer parallel Schwachstellen in lokalen SharePoint-Servern ausnutzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/sharepoint-zwei-ransomware-gruppen
-
Cybercrime-as-a Microsoft und BKA gehen gegen Amadey und StealC vor
Microsoft, BKA, Europol und weitere Partner sind gegen eine ganze Cybercrime-Maschinerie vorgegangen. First seen on computerbase.de Jump to article: www.computerbase.de/news/internet/cybercrime-as-a-service-microsoft-und-bka-gehen-gegen-amadey-und-stealc-vor.98107
-
Microsoft gives Windows 10 users an unexpected extra year of free security updates
Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/microsoft-windows-10-free-security-updates-esu-program/
-
Windows Secure Boot Certificate Expiry Exposes Billions of PCs to Bootkit and Firmware Security Risks
Microsoft’s long-planned Secure Boot certificate rollover has reached a critical milestone, impacting more than just routine updates. The Microsoft Corporation KEK CA 2011 expired on June 24, 2026, the Microsoft UEFI CA 2011 expires on June 27, 2026, and the Microsoft Windows Production PCA 2011 is scheduled to expire on October 19, 2026. This requires…
-
Microsoft verlängert ESU-Programm: Windows 10 erhält ein Jahr mehr kostenlose Sicherheitsupdates
Microsoft aktualisiert das ESU-Programm für Privatkunden: Kostenlose Sicherheitsupdates für Windows 10 gibt es ein Jahr länger als bisher zugesichert. First seen on golem.de Jump to article: www.golem.de/news/microsoft-verlaengert-esu-programm-windows-10-erhaelt-ein-jahr-mehr-kostenlose-sicherheitsupdates-2606-210205.html
-
Microsoft verlängert ESU-Programm: Windows 10 erhält ein Jahr mehr kostenlose Sicherheitsupdates
Microsoft aktualisiert das ESU-Programm für Privatkunden: Kostenlose Sicherheitsupdates für Windows 10 gibt es ein Jahr länger als bisher zugesichert. First seen on golem.de Jump to article: www.golem.de/news/microsoft-verlaengert-esu-programm-windows-10-erhaelt-ein-jahr-mehr-kostenlose-sicherheitsupdates-2606-210205.html
-
Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
Microsoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime “supply chain.” Europol said more than 300 servers were targeted. First seen on therecord.media Jump to article: therecord.media/stealc-amadey-socgholish-malware-takedown-europol-microsoft
-
Commvault, Microsoft partner to bring cyber resilience services natively to Azure
First seen on scworld.com Jump to article: www.scworld.com/brief/commvault-microsoft-partner-to-bring-cyber-resilience-services-natively-to-azure
-
Commvault, Microsoft partner to bring cyber resilience services natively to Azure
First seen on scworld.com Jump to article: www.scworld.com/brief/commvault-microsoft-partner-to-bring-cyber-resilience-services-natively-to-azure
-
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure. Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver,…
-
Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers
Europol and Microsoft disrupted malware infrastructure linked to 27 million stolen login credentials and 140,000 infected computers in a global cybercrime network. The post Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-europol-microsoft-malware-takedown-emea-eu/
-
Malicious Edge extension abuses Native Messaging as bridge to malware
A malicious Microsoft Edge extension dubbed ‘Edgecution’ has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/
-
Manipulierte Edge-Erweiterung schleust Ransomware ein
Eine manipulierte Microsoft-Edge-Erweiterung namens Edgecution umgeht die Browser-Sandbox und installiert eine Python-Hintertür für Ransomware-Angriffe. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/edge-erweiterung-ransomware
-
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Tags: attack, breach, credentials, cybercrime, finance, fraud, infrastructure, law, malware, microsoft, network, ransomwareA coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.”The main common goal was to disrupt the ‘assembly lines’ cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure,” Europol said in First seen…
-
Microsoft, Europol lead international takedown against infostealer malware
Cybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-europol-international-takedown-infostealer-malware/823655/
-
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete
Imagine completing a two-factor authentication check on a real Microsoft login page and still handing a criminal full access to your email account. That is not a hypothetical. According to new research published this week by cybersecurity company Huntress, it happened across hundreds of organisations in the first four months of 2026 and the victims…
-
Amadey, StealC malware operations disrupted in Operation Endgame action
Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/
-
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Tags: apache, attack, control, cybersecurity, flaw, github, google, microsoft, open-source, supply-chainCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and First seen…
-
In a first, a court takedown goes after two cybercrime tools at once
Microsoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-amadey-stealc-takedown/
-
Overwhelming support for Microsoft SMS designation in CMA responses
Some 25 organisations back Strategic Market Status for Microsoft’s business software ecosystem, while the Open Cloud Coalition estimates £60m in annual public sector costs First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645005/Overwhelming-support-for-Microsoft-SMS-designation-in-CMA-responses
-
Payouts King Initial Access Broker Deploys Edgecution Malware Through Malicious Edge Extension
A concerted campaign by an initial access broker with ties to the Payouts King ransomware ecosystem that leverages a novel browser-based delivery technique to establish persistent host-level control. The actor deploys a malicious Microsoft Edge extension dubbed >>Edgecution<< which abuses the Chrome native messaging protocol to reach a Python backdoor running on the endpoint, effectively…
-
PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability
A proof-of-concept exploit has been released for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability in the Microsoft Exchange Server’s Exchange Web Services (EWS) InstallApp operation. This vulnerability poses risks to organisations that have not yet deployed the security updates from June 2026. The flaw affects Exchange Server versions 2016 CU23, 2019 CU14 and CU15, and…
-
Microsoft Weighs DeepSeek for Copilot Amid Security Debate
Lower-Cost AI Model Could Cut Agent Costs But Raise Enterprise Risks. Microsoft is testing alternative AI models, including China’s DeepSeek v4, to reduce the cost of running Copilot Cowork’s agentic workloads. While cheaper inference pricing could appeal to enterprises, security experts warn that governance, validation and oversight costs may offset any savings. First seen on…
-
Microsoft Weighs DeepSeek for Copilot Amid Security Debate
Lower-Cost AI Model Could Cut Agent Costs But Raise Enterprise Risks. Microsoft is testing alternative AI models, including China’s DeepSeek v4, to reduce the cost of running Copilot Cowork’s agentic workloads. While cheaper inference pricing could appeal to enterprises, security experts warn that governance, validation and oversight costs may offset any savings. First seen on…
-
Windows 11 KB5095093 update rolls out new PointTime restore feature
Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Point-in-Time restore feature. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5095093-update-rolls-out-new-point-in-time-restore-feature/

