Tag: microsoft
-
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, microsoft, remote-code-execution, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug…
-
Microsoft’s ‘Project Perception’ Could Challenge Anthropic’s Mythos in AI Security
Microsoft is reportedly developing Project Perception, a lower-cost AI security tool that would use multiple models to identify enterprise vulnerabilities. The post Microsoft’s ‘Project Perception’ Could Challenge Anthropic’s Mythos in AI Security appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-project-perception-ai-security-tool/
-
Warum KI-gestützte Schwachstellensuche das Patchen unter Druck setzt
Der Juli-Patchday von Microsoft fällt außergewöhnlich umfangreich aus. Insgesamt wurden 570 Schwachstellen behoben, davon 57 als kritisch und 510 als wichtig eingestuft. Darunter befinden sich drei Zero-Day-Lücken, von denen zwei bereits aktiv in Angriffen ausgenutzt werden und eine öffentlich bekannt gemacht wurde. Auffällig ist zudem die enorme Zahl von 468 Schwachstellen in Microsoft-Edge/Chromium, von denen…
-
Passwort”‘Spray”‘Kampagne – Hacker starten 81 Millionen Login-Versuche gegen Microsoft 365
First seen on security-insider.de Jump to article: www.security-insider.de/passwort-spraying-81-mio-angriffe-microsoft-365-rocp-mfa-a-429ec8a48b72ec905e4e2cfb85f19fb1/
-
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable…
-
Kurz nach Microsoft-Patchday: Schadcode-Attacken auf Sharepoint-Server beobachtet
Angreifer nutzen eine kritische Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten ihre Systeme zügig absichern. First seen on golem.de Jump to article: www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-luecke-wird-aktiv-ausgenutzt-2607-211000.html
-
Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt
Angreifer nutzen eine kritische Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten ihre Systeme zügig absichern. First seen on golem.de Jump to article: www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-luecke-wird-aktiv-ausgenutzt-2607-211000.html
-
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains…
-
Windows Server 2022 reach end of mainstream support in 90 days
Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-server-2022-reach-end-of-mainstream-support-in-90-days/
-
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: The vulnerability CVE-2023-4346 (CVSS…
-
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization First seen…
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…
-
Streamer verliert Microsoft-Account nach Hack: Warum 25 Jahre Daten nicht wiederhergestellt werden können
Tags: microsoftFirst seen on t3n.de Jump to article: t3n.de/news/streamer-verliert-microsoft-account-nach-hack-25-jahre-daten-1752992/
-
Microsoft ändert seinen Anmeldevorgang: Was an deinem Arbeitscomputer bald anders läuft
Tags: microsoftFirst seen on t3n.de Jump to article: t3n.de/news/microsoft-aendert-seinen-anmeldevorgang-was-an-deinem-arbeitscomputer-bald-anders-laeuft-1752897/
-
OAuth Client ID Spoofing Enables Stealthy Cloud Account Enumeration
Proofpoint found attackers are using OAuth client ID spoofing to stealthily enumerate Microsoft Entra ID accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oauth-client-id-spoofing-enables-stealthy-cloud-account-enumeration/
-
Gesperrtes Konto: Doch kein endgültiger Datenverlust bei Microsoft
Tags: microsoftMicrosoft erklärte ein Konto für unwiederbringlich verloren. Jetzt ist es mitsamt Onedrive-Fotos und Spielen wieder da. First seen on golem.de Jump to article: www.golem.de/news/gesperrtes-konto-doch-kein-endgueltiger-datenverlust-bei-microsoft-2607-210958.html
-
Windows 11 24H2 Home and Pro reach end of support in 90 days
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-90-days/
-
Microsoft makes Windows SSO prompts easier to manage
Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/windows-sso-policy-admin-control/
-
Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record
The company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-patch-tuesday-july-2026/
-
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update/
-
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update/
-
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
-
Windows 11 KB5101650 & KB5099414 cumulative updates released
Microsoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb5099414-cumulative-updates-released/
-
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry.The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors…
-
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/
-
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/
-
Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts
Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique exploits how Entra ID processes the client_id parameter in OAuth authentication requests. Every registered OAuth application is assigned a globally unique application identifier, and…
-
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.”An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,” First seen on…
-
Microsoft starts testing cleaner Windows Search without ads
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-starts-testing-cleaner-windows-search-without-ads/
-
No one knows how many old shims can still bypass UEFI Secure Boot
The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/

