Tag: microsoft
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first flaw added to the KeV…
-
Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud
Also, Spain Fines 23andMe Over 2023 Data Breach. This week: Zelle can’t transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania’s land registry, Spain fined 23andMe, Australia’s Origin Energy data breach and pirate World Cup streaming sites seized. Malware found hiding in Microsoft 365 calendars. First…
-
Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained
Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices. The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-security-cheat-sheet/
-
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services/
-
Microsoft Copilot Deployments Delayed Over Security Concerns
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-copilot-delayed-over/
-
Panne bei Microsoft: Exchange Online schiebt harmlose Postfächer in die Quarantäne
Bei Exchange Online landen seit Tagen ganze E-Mail-Postfächer in der Quarantäne. Microsoft hat wohl eine Infrastrukturänderung verhunzt. First seen on golem.de Jump to article: www.golem.de/news/e-mail-panne-bei-microsoft-exchange-schiebt-harmlose-postfaecher-in-die-quarantaene-2607-211197.html
-
EPanne bei Microsoft: Exchange schiebt harmlose Postfächer in die Quarantäne
Bei Exchange Online landen seit Tagen ganze E-Mail-Postfächer in der Quarantäne. Microsoft hat wohl eine Infrastrukturänderung verhunzt. First seen on golem.de Jump to article: www.golem.de/news/e-mail-panne-bei-microsoft-exchange-schiebt-harmlose-postfaecher-in-die-quarantaene-2607-211197.html
-
Flaws in Passkey Implementation Show Old Attacks Still Work
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
-
Microsoft working to fix Exchange Online mailbox quarantine issue
Tags: microsoftMicrosoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-exchange-online-mailbox-quarantine-issue/
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly.…
-
Microsoft und Mistral erweitern Partnerschaft – Milliarden-Deal: Microsoft und Mistral AI stärken Europas KI
First seen on security-insider.de Jump to article: www.security-insider.de/milliarden-deal-microsoft-und-mistral-ai-staerken-europas-ki-a-1d59a04a7b78184a4ce93f544e9337a6/
-
Zugangsdaten erneuern: SharePoint-Schwachstelle bedroht Unternehmensnetze
Sicherheitsforscher beobachten Angriffe auf Microsoft SharePoint über die Schwachstelle CVE-2026-50522. Angreifer entwenden dabei Maschinenschlüssel. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/sharepoint-schwachstelle-2
-
Microsoft ends extended security updates for Exchange 2016 and 2019 in October 2026
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-ends-extended-security-updates-for-exchange-2016-and-2019-in-october-2026
-
Bundeskriminalamt zerschlägt Phishing-Plattform Kratos
Am 20. Juli 2026 zerschlugen Bundeskriminalamt und ZIT (Zentralstelle zur Bekämpfung der Internetkriminalität) gemeinsam mit US-Behörden im Rahmen der Operation ‘Olympus Blade” die Infrastruktur von Kratos einer Phishing-as-a-Service-Plattform, die für einen Großteil der aktuellen Microsoft-365-Credential-Diebstähle verantwortlich war. Der Entwickler und technische Administrator wurde in Indonesien verhaftet, über 200 Server wurden abgeschaltet. Zuvor nutzen mehr […]…
-
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-sharepoint-attack-new-exploit/825797/
-
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-esu-program-ends-in-october/
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities,…
-
Xbox: Microsoft will Support für gehackte Konten verbessern
Laut einem Bericht arbeitet Microsoft an besseren Prozessen für gehackte Konten. Bislang konnten Betroffene dauerhaft den Zugriff verlieren. First seen on golem.de Jump to article: www.golem.de/news/xbox-microsoft-will-support-fuer-gehackte-konten-verbessern-2607-211149.html
-
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal…
-
Zwei Drittel der Unternehmen verschieben die Einführung von Microsoft Copilot wegen Datenschutzrisiken
Zwei von drei (66 %) Unternehmen haben Bedenken, dass Microsoft Copilot vertrauliche Daten offenlegen könnte und haben deshalb die Einführung des KI-Assistenten verschoben oder komplett gestrichen. Zudem befürchten nahezu drei Viertel (73 %) der Benutzer, dass KI bereits intern sensible Informationen preisgibt. Zu diesen und weiteren Ergebnissen kommt der neue Report »State of Microsoft… First…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools returns…
-
HollowGraph malware uses Microsoft 365 calendar for command and control
First seen on scworld.com Jump to article: www.scworld.com/brief/hollowgraph-malware-uses-microsoft-365-calendar-for-command-and-control
-
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization…
-
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
-
Künstliche Intelligenz: Microsoft und Mistral arbeiten bei KI in Europa zusammen
Microsoft und Mistral arbeiten künftig zusammen. Mistrals KI-Modelle sind ab sofort in Microsofts Entwicklungsplattformen und in Copilot Studio verfügbar. First seen on golem.de Jump to article: www.golem.de/news/kuenstliche-intelligenz-microsoft-und-mistral-abreiten-bei-ki-in-europa-zusammen-2607-211119.html
-
Zwei Drittel der Unternehmen verschieben die Einführung von Microsoft-Copilot wegen Datenschutzrisiken
Zwei von drei (66 %) Unternehmen haben Bedenken, dass Microsoft-Copilot vertrauliche Daten offenlegen könnte und haben deshalb die Einführung des KI-Assistenten verschoben oder komplett gestrichen. Zudem befürchten nahezu drei Viertel (73 %) der Benutzer, dass KI bereits intern sensible Informationen preisgibt. Zu diesen und weiteren Ergebnissen kommt der neue Report ‘State of Microsoft 365 Security…
-
Microsoft und Mistral erweitern Partnerschaft für souveräne KI
Microsoft und Mistral haben eine neue, mehrjährige Vereinbarung im Umfang von mehreren Milliarden Dollar geschlossen. Im Mittelpunkt stehen zusätzliche KI-Rechenkapazitäten für Microsoft in Europa, die Integration aktueller Mistral-Modelle in Microsofts KI-Plattformen sowie neue Möglichkeiten für Unternehmen und regulierte Branchen, führende KI-Anwendungen in unterschiedlichen Betriebsumgebungen umzusetzen. Die Vereinbarung soll Unternehmen mehr Wahlfreiheit und Kontrolle geben: Sie…

