Tag: microsoft
-
Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/
-
Sicherheit für Microsoft-365 Coreview startet Intelligence-Labs
Der Spezialist für den Schutz und das Management von Microsoft-365-Tenants, Coreview, hilft mit seinen neuen Intelligence-Labs Sicherheitsexperten dabei, die Prozesse in ihren Microsoft-Tenants zu verstehen und bestehende sowie neu auftretende Sicherheitslücken zu schließen. Hierfür werden die Sicherheitsforscher unter der Leitung von Kasper Lindgaard technische Forschungsergebnisse und praktische Leitfäden zur Sicherheit von Microsoft-365 veröffentlichen. Die Einführung…
-
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication. First seen on hackread.com Jump to article: hackread.com/microsoft-password-reset-portal-leak-account-details/
-
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/
-
Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/75-organizations-microsoft-365/
-
Microsoft fixes bug that broke Windows File History backup feature
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/
-
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection capabilities in a platform designed for AI-assisted, continuous defense. The company’s premise is direct: traditional SOC architectures cannot match adversaries that use AI agents to automate reconnaissance, intrusion execution, lateral movement, and operational decision-making at machine speed.…
-
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.”The campaign compromised 7 accounts First seen on thehackernews.com Jump…
-
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company originally described it as a spoofing issue with a CVSS score of 6.5. In reality, it is an authenticated RCE flaw rated 8.8. That gap matters, because security teams that trusted the first label may…
-
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/
-
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
-
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. First seen on cyberscoop.com Jump to article: cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used…
-
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. First seen on therecord.media Jump to article: therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
-
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/
-
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
-
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender UpdateDoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher…
-
Warum Sicherheitsverantwortliche Microsoft-365 verstärkt in den Blick nehmen sollten
Cyberkriminelle zielen immer häufiger direkt auf den Microsoft-365-Tenant ab. Sie manipulieren Identitäten, verschlüsseln Daten in der Cloud und erpressen Unternehmen, ohne auch nur eine einzige Zeile herkömmlicher Malware einzusetzen. Für Banken, Versicherungen und andere regulierte Unternehmen ist dies kein düsteres Zukunftsszenario. Es ist die Realität im Jahr 2026 und den meisten Unternehmen fehlt die […]…
-
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been First seen…
-
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITY\SYSTEM. Public proof-of-concept (PoC) code for CVE-2026-32996 was released on September 14, increasing the urgency for organizations to patch affected Veeam deployments. CVE-2026-32996 impacts Veeam Agent for Microsoft Windows…
-
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
-
Windows 11 26H1 Security Update Expands Secure Boot Certificate Protection
Microsoft has released the cumulative security update for September 2026 for Windows 11 version 26H1. This update expands the range of systems that can automatically receive new Secure Boot certificates. KB5124012, released on September 8, brings devices to OS Build 28000.2954. It includes enhanced, high-confidence device-targeting data to improve certificate deployment coverage across supported PCs…
-
Microsoft gesteht: Update-Panne macht Dateiversionsverlauf von Windows kaputt
Die Windows-Updates von September ziehen allerhand Probleme nach sich. Auch der Dateiversionsverlauf funktioniert nicht mehr richtig. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-update-panne-macht-dateiversionsverlauf-von-windows-kaputt-2609-213294.html
-
Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027
Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing-resistant authentication. This change affects workers who currently use a registered phone number and a one-time SMS code as their initial sign-in credential, a passwordless flow utilized by frontline organizations. Microsoft…
-
DavMail 7.0.0 puts most of its work into Microsoft Graph
Anyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/davmail-7-0-0-microsoft-graph/
-
Microsoft to retire Microsoft 365 Companion apps in December
Tags: microsoftMicrosoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/
-
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when…
-
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/
-
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/

