Tag: microsoft
-
No one knows how many old shims can still bypass UEFI Secure Boot
The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/
-
Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Proofpoint details how attackers spoof OAuth client IDs to probe Microsoft Entra accounts, test credentials and bypass common sign-in detections at cloud scale. First seen on hackread.com Jump to article: hackread.com/microsoft-entra-accounts-oauth-client-id-spoofing/
-
Daten im toten Winkel – Datensicherheit: Warum Microsoft Purview nur die halbe Miete ist
Tags: microsoftFirst seen on security-insider.de Jump to article: www.security-insider.de/purview-saas-daten-mittelstand-absichern-a-54596c526b319e294f043d28a1b6adcb/
-
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/
-
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections, establish persistence, and exfiltrate CRM data at scale. The activity, observed from mid-202520252025 through mid-202620262026, affected organizations in retail, education, and manufacturing. Microsoft emphasized that the campaigns did not exploit an…
-
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version.The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single…
-
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-entra-user-enumeration-bypass-proofpoint/825052/
-
Hackers have found a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-entra-user-enumeration-bypass-proofpoint/825052/
-
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing First seen on thehackernews.com Jump to article:…
-
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/novel-spoofing-technique-targets/
-
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/
-
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Microsoft demystifies how Windows updates work
Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/how-microsoft-windows-updates-work/
-
Microsoft Tests AI-Powered Copilot Tool to Diagnose Windows 11 Performance Issues
Microsoft is gradually rolling out an optional Copilot feature called PC Insights, which provides the AI assistant with access to real-time information about Windows 11 hardware and performance. This feature, first reported by Windows Latest, is currently being tested with users in the United States and is not yet widely available. PC Insights aims to…
-
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup
The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-365-fake-passkey-setup-enrollment/
-
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
-
Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/
-
SECARDEO certEntra v2 automatisiert S/MIME- und CBA-Zertifikate für Microsoft Entra ID
Tags: microsoftFür Unternehmen bedeutet das: Zertifikatsmanagement wird nicht nur zur Frage der heutigen IT-Sicherheit, sondern auch zur Vorbereitung auf kommende kryptografische Anforderungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/secardeo-certentra-v2-automatisiert-s-mime-und-cba-zertifikate-fuer-microsoft-entra-id/a45714/
-
SECARDEO certEntra v2 automatisiert S/MIME- und CBA-Zertifikate für Microsoft Entra ID
Tags: microsoftFür Unternehmen bedeutet das: Zertifikatsmanagement wird nicht nur zur Frage der heutigen IT-Sicherheit, sondern auch zur Vorbereitung auf kommende kryptografische Anforderungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/secardeo-certentra-v2-automatisiert-s-mime-und-cba-zertifikate-fuer-microsoft-entra-id/a45714/
-
Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection Engine used by Defender. The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal…
-
Microsoft to retire the OWA Light client in Exchange Server
Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-announces-owa-light-retirement-in-exchange-server/
-
‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies
Microsoft co-signed a malicious kernel driver, and now it’s being used to kill security software in ransomware attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…

