Tag: microsoft
-
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can’t make an omelet without breaking a few eggs, and you can’t patch nearly 1,000 CVEs without a few glitches. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday
-
Microsoft’s New AI Rules Say Models Must Never Resist Human Shutdown
Microsoft has drafted a “Humanist AI” code requiring future models to accept human shutdown, follow non-negotiable safety rules, and remain under control. The post Microsoft’s New AI Rules Say Models Must Never Resist Human Shutdown appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-humanist-ai-code-human-control/
-
Microsoft deckt CEO- und CFO-Betrugswelle auf
Über eine Million Betrugs-E-Mails imitierten CEOs und CFOs, um Finanzabteilungen zu gefälschten Banküberweisungen zu bewegen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-ceo-cfo-betrug
-
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Tags: cloud, credentials, cybersecurity, data-breach, exploit, flaw, infrastructure, Internet, microsoft, serviceCybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs.The First seen on thehackernews.com…
-
Microsoft sets security and safety rules for its AI models
Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/microsoft-ai-safety-rules-humanist-ai-code-of-conduct/
-
Microsoft Releases Emergency Patch to Fix RDS Vulnerability
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/
-
Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities. The program prioritizes flaws that have a direct and demonstrable security impact in supported cloud services, including cross-tenant issues that could compromise isolation between customer environments. Microsoft Offers $60,000 Bounty…
-
12 Best CNAPP Platforms Compared (2026): Features Pricing
Quick Answer: CNAPP quotes swing 23× on identical estates because “workload” definitions differ. Microsoft Defender for Cloud is the only major with fully published per-resource rates; Wiz and Orca quote per workload; Prisma Cloud uses credits; challengers like Upwind and Uptycs undercut on runtime-first models. This guide compares all 12 on how the money actually…
-
11 Best CSPM Tools Compared (2026): Features Pricing
Quick Answer: Wiz leads agentless attack-path CSPM; Prisma Cloud leads breadth; Microsoft Defender for Cloud offers a free foundational tier plus published per-resource plans; Orca pioneered agentless SideScanning. Consolidation note: Ermetic is now Tenable Cloud Security and Lacework is now Fortinet’s FortiCNAPP our list reflects both. Misconfiguration a public bucket, an over-permissive role, an exposed…
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
Microsoft Releases Emergency Patch to Fix RDS Snafu
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-passkey-phishing-microsoft-365-cloud-data/
-
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month’s security updates, along with Hyper-V and USB audio problems on some Windows versions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/
-
Phishing ohne Webserver: Neuartige Browser-Angriffe aufgedeckt
Angreifer generieren gefälschte Anmeldeseiten mittels Blob-URLs direkt im Arbeitsspeicher der Opfer. Der Missbrauch vertrauenswürdiger Microsoft-Dienste hebelt klassische Filter aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-ohne-webserver
-
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsofts-patching/
-
RDP, Sound und mehr: Windows-Updates bereiten Nutzern allerhand Probleme
Laut Microsoft lösen die neuen Windows-Updates Probleme mit Linux-VMs, USB-Audio und RDP-Verbindungen aus. Doch da scheint noch mehr kaputt zu sein. First seen on golem.de Jump to article: www.golem.de/news/rdp-sound-und-mehr-windows-updates-bereiten-nutzern-allerhand-probleme-2609-212982.html
-
Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together
Originally published at Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together by Mike Anderson. Microsoft 365 and Google Workspace have become essential to how businesses communicate, collaborate, and operate. But as these platforms have become… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/protecting-microsoft-365-and-google-workspace-why-email-security-and-backup-belong-together/
-
September updates cause RDS failures on Windows Server
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/
-
Detecting OAuth consent phishing in Microsoft 365 audit logs
OAuth consent phishing is a practical identity attack that abuses the trust users place in application consent prompts. Instead of stealing a password directly, the attacker persuades a user to grant a malicious app access to mailbox data, profile information,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-oauth-consent-phishing-in-microsoft-365-audit-logs/
-
September updates break audio on some Windows PCs
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
Saturday Security: AI Industrializes Phishing
This week’s Saturday Security Story shows how AI is industrializing an old scam, and doing it at a scale that should get everyone’s attention. Microsoft spotted a campaign that blasted more than 1 million fraudulent emails across a three-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saturday-security-ai-industrializes-phishing/

