Tag: microsoft
-
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows authenticated low-privileged users to access and read arbitrary files from vulnerable Exchange servers. The vulnerability, discovered by security researcher Batuhan Er from HawkTrace, affects Microsoft Exchange Server 2019. Microsoft Exchange SSRF…
-
Behörde warnt: Microsoft-Sharepoint-Server werden attackiert
Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln. First seen on golem.de Jump to article: www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden-attackiert-2607-210462.html
-
US cyber agency warns over forgotten SharePoint flaw
An RCE vulnerability in Microsoft SharePoint that was mistakenly omitted from the May Patch Tuesday bulletin is being exploited in the wild, says Cisa. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645307/US-cyber-agency-warns-over-forgotten-SharePoint-flaw
-
Angriffe auf Azure-CLI: Millionen Passwort-Angriffe auf Microsoft-Konten
Ein massiver Password-Spray-Angriff auf das Azure-CLI kompromittierte 78 Microsoft-Konten. Angreifer nutzten ein veraltetes OAuth-Verfahren als Bypass. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/angriffe-auf-azure-cli
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…
-
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/
-
Microsoft fixes bug that removed Copilot buttons in Outlook
Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-removed-copilot-button-in-outlook/
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
CISA Adds Actively Exploited Microsoft SharePoint Vulnerability to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a newly discovered vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition highlights the active exploitation risks present in enterprise environments. The vulnerability falls under the CWE-502 (Deserialization of Untrusted Data) category, allowing an authenticated attacker to…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-perplexity-chrome-extension-searches/
-
Microsoft SharePoint RCE flaw now actively exploited
CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
-
81 Millionen Anmeldeversuche: Massenangriff auf Microsoft-Konten
Tags: microsoftForscher warnen vor einer neuen Angriffswelle auf Microsoft-365-Konten. Die Angreifer testen massenhaft Zugangsdaten durch, teilweise mit Erfolg. First seen on golem.de Jump to article: www.golem.de/news/81-millionen-anmeldeversuche-massenangriff-auf-microsoft-konten-2607-210424.html
-
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue First seen…
-
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June 12 and June 26, 2026. According to researchers from Huntress, the activity primarily originates from…
-
Cordyceps gefährdet CI/CD-Pipelines auf GitHub – Cordyceps trifft Repositories von Microsoft, Google und anderen
First seen on security-insider.de Jump to article: www.security-insider.de/cordyceps-github-cicd-pipeline-microsoft-google-schwachstelle-a-5937c5d6b9fbe3379be3997686acb4a6/
-
Quantum Breakthroughs Compress Post-Quantum Computing Timeline
Microsoft, Google and AWS cite major gains in reliability and error correction.. Rapid advances in quantum hardware, AI-assisted error correction and fault-tolerant architectures from Microsoft, Google and Amazon are accelerating expectations for practical quantum computing, increasing pressure on organizations to adopt crypto-agility and prepare for post-quantum encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quantum-breakthroughs-compress-post-quantum-computing-timeline-a-32137
-
Phishing Tactics Target Session Tokens and Deliver Malware
Barracuda found phishing attacks increasingly abuse Microsoft authentication, session tokens, and fileless malware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/phishing-tactics-target-session-tokens-and-deliver-malware/
-
Cisco Talos Exposes ARToken Microsoft 365 Phishing Kit
Cisco Talos uncovered ARToken, a Microsoft 365 phishing platform built for persistent access and BEC attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cisco-talos-exposes-artoken-microsoft-365-phishing-kit/
-
Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan
Microsoft and Trend Micro found hotel phishing attacks using fake guest complaints and photo links to target staff in Japan. The post Microsoft Uncovers Widespread Hotel Phishing Campaign in Japan appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-hotel-phishing-apac-japan/
-
Azure Password-Spraying Attack Bypasses MFA Defenses
Threat Actor Uses Deprecated OAuth 2.0 Authentication Flow. Attackers behind a password-spraying campaign targeting Microsoft Office 365 accounts have amassed dozens of victims by abusing a deprecated feature in OAuth 2.0 to generate access tokens, in some cases sidestepping multifactor authentication controls, warn researchers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/azure-password-spraying-attack-bypasses-mfa-defenses-a-32128
-
Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users. First seen on hackread.com Jump to article: hackread.com/fake-google-notes-browser-extension-swap-crypto-wallets/
-
Hackers target Microsoft 365 accounts with 81 million login attempts
An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/
-
Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs
81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft Azure CLI environments since June 12, 2026. A password spray attack is when attackers try a small number of common passwords across many accounts instead of many passwords…
-
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer allows attackers to escalate privileges locally in Microsoft Defender. The vulnerability, along with two other zero-days dubbed…
-
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Talos has identified “ARToken,” a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/
-
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
Microsoft on Tuesday said it’s accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected.”Advances in quantum research and development have shifted the risk horizon,” Mark Russinovich, chief technology officer of Microsoft Azure, said. “We believe First seen on thehackernews.com…
-
The ARToken phishing panel targets Microsoft 365 accounts
Accounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/01/artoken-phishing-panel-microsoft-365-accounts/
-
Microsoft fixes GIF functionality in the Windows Emoji Panel
Microsoft has fixed the GIF functionality in the Emoji Panel for Windows 11 and Windows Server users after the provider shut down its service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-gif-functionality-in-the-windows-emoji-panel/
-
Microsoft Accelerates Quantum-Safe Push with New Timeline
Microsoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC) First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-accelerates-quantumsafe/

