Tag: microsoft
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
Update gegen Rogueplanet: Microsoft reagiert auf gefährlichen Defender-Exploit
Der Rogueplanet-Exploit verleiht Angreifern unter Windows weitreichende Systemrechte. Ein Update für den Microsoft Defender soll schützen. First seen on golem.de Jump to article: www.golem.de/news/update-gegen-rogueplanet-microsoft-reagiert-auf-gefaehrlichen-defender-exploit-2607-210674.html
-
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/
-
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
Attackers use Microsoft Teams voice calls to deliver EtherRAT malware
First seen on scworld.com Jump to article: www.scworld.com/brief/attackers-use-microsoft-teams-voice-calls-to-deliver-etherrat-malware
-
The Most Elusive Criminal Quality: Anonymity
Suspected Scattered Spider Member Reportedly Unmasked After Making Death Threat How did investigators unmask a 19-year-old suspected Scattered Spider extortionist? Amateur sleuths have highlighted Microsoft-gathered device telemetry in charging documents. But a researcher said he was quickly unmasked and tracked for years, after he sent her a death threat. First seen on govinfosecurity.com Jump to…
-
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.”The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the…
-
Windows 11 26H2 Enables Backup Policy to Restore User Apps and Settings
Microsoft has confirmed a significant policy change in the upcoming Windows 11 version 26H2. This update introduces a new default behavior for Windows settings backup, which could affect enterprise security baselines and device resilience strategies. According to an official announcement published on July 6, 2026, the Windows settings backup policy will change from being disabled…
-
UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories
More than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government’s Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-gov-launches-cyber-resilience/
-
M&S among first businesses to sign UK government’s resilience pledge
Marks & Spencer joins the likes of Accenture, Microsoft and Vodafone by committing to take practical steps to improve cyber standards through the government’s voluntary Cyber Resilience Pledge First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645538/MS-among-first-businesses-to-sign-UK-governments-resilience-pledge
-
Microsoft to enable Windows settings backup by default for orgs
Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-to-enable-windows-backup-for-organizations-by-default/
-
Microsoft Introduces Execution Containers to Secure AI Agents on Windows
Microsoft has introduced a new security architecture to safeguard autonomous AI agents on Windows, unveiling the Microsoft Execution Containers (MXC) SDK at Build 2026. The move reflects a growing industry concern: as AI agents evolve from passive assistants into autonomous systems capable of executing code, accessing files, and orchestrating workflows, they introduce significant security and…
-
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-testing-new-cloud-rebuild-windows-11-recovery-feature/
-
Microsoft wants to keep your AI agents from going rogue
Microsoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/microsoft-execution-containers-ai-agents-constraints/
-
Microsoft Edge High-Severity Vulnerability Allows Remote Code Execution
Microsoft has disclosed a high-severity remote code execution (RCE) vulnerability in its Chromium-based Edge browser, identified as CVE-2026-57992. This vulnerability could allow attackers to execute arbitrary code on affected systems under specific conditions. Publicly disclosed on July 3, 2026, it is classified as CWE-416 (Use-After-Free), which is a memory safety flaw. This issue occurs when…
-
Microsoft Teams allows users to turn off AI features
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-teams-allows-users-to-turn-off-ai-features
-
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/
-
Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap
A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled. The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-azure-cli-mfa-gap/
-
Sicherheitsdienst speziell für KI-Agenten in Microsoft-Umgebungen
Bluevoyant gibt die Einführung seines ‘Microsoft Agent 365 Security Deployment Service” bekannt, des ersten professionellen Dienstleistungsprogramms, das Unternehmen dabei unterstützt, die in ihrer Microsoft-Umgebung ausgeführten KI-Agenten zu identifizieren, zu verwalten und abzusichern. Die Einführung des Dienstes erfolgt zu einem Zeitpunkt, zu dem Unternehmen weltweit darum wetteifern, möglichst rasch KI-Agenten einzuführen schneller als ihre Sicherheitsteams […]…
-
Hackers Use Trusted Microsoft Domain and One-Time Codes to Hijack Corporate Accounts
A rising phishing technique is exploiting a legitimate Microsoft authentication flow to hijack corporate accounts without stealing passwords. Attackers are weaponizing the OAuth 2.0 Device Authorization Grant commonly used to sign in input-constrained devices via a one-time user code to trick victims into approving access on Microsoft’s own domain. Because the final authentication occurs on…
-
Microsoft Warns Windows 11 Enterprise Devices May Boot to Black Screen After Updates
Microsoft has issued a warning to enterprise administrators about a critical issue affecting Windows 11 systems. This problem may cause devices to boot to a black screen or experience severe shell failures following recent cumulative updates. The issue, documented under KB5072911, affects Windows 11 versions 24H2 and 25H2 when updates released on or after July…
-
BlueVoyant startet Sicherheitsdienst für KI-Agenten in Microsoft-Umgebungen
BlueVoyant stellt den Microsoft Agent 365 Security Deployment Service vor. Der Dienst soll KI-Agenten in Microsoft-Umgebungen sichtbar, steuerbar und sicherer machen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/bluevoyant-startet-sicherheitsdienst-fuer-ki-agenten-in-microsoft-umgebungen/a45674/
-
Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts
A Mac-targeting ClickFix campaign amplified through a verified X sponsored ad, and a novel browser-based hijack technique called ConsentFix that exfiltrates Microsoft 365 session tokens without traditional malware. Researchers at Jamf and Malwarebytes tracked the X incident where a verified account ran a sponsored advertisement promoting a macOS utility dubbed “DynamicLake” a lookalike for legitimate…
-
ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit
A new phishing-as-a-service (PhaaS) platform dubbed “ARToken” appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/
-
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows authenticated low-privileged users to access and read arbitrary files from vulnerable Exchange servers. The vulnerability, discovered by security researcher Batuhan Er from HawkTrace, affects Microsoft Exchange Server 2019. Microsoft Exchange SSRF…
-
Behörde warnt: Microsoft-Sharepoint-Server werden attackiert
Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln. First seen on golem.de Jump to article: www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden-attackiert-2607-210462.html

