< ciso
brief />
Tag Banner

All news with #microsoft tag

1054 articles

Multiple Vendor Vulnerabilities and Vendor Patches

🔒 Cisco Talos disclosed multiple vulnerabilities affecting Adobe, Apple, Foxit Reader, and Microsoft. The vendors have issued patches in accordance with Cisco’s disclosure policy. Snort rule updates are available to detect exploitation, and Talos posts ongoing vulnerability advisories on its site. Affected components include Photoshop installer, macOS CoreWLAN, Foxit PDF JavaScript features, and several Windows kernel drivers.
read more →

Three Lessons from Frontier AI Vulnerability Research

🔍 Microsoft Security’s FORGE Lab advances AI-native vulnerability research across Windows and open-source projects, emphasizing autonomy, defense through offense, and ecosystem-focused outcomes. From May to September 2026, FORGE reported 140 Windows CVEs and 155 validated reports across 23 open-source projects, including the Linux kernel. The post argues that discovery scale shifts the bottleneck from model intelligence to reproducible validation, remediation, and integration with engineering and servicing workflows.
read more →

Microsoft Outlook to Block .msix and .msixbundle Files

🛡️ Microsoft will add .msix and .msixbundle attachments to the default blocked file types in Outlook on the web and the new Outlook for Windows, starting with a rollout to Exchange Online in early November and GA by mid-November. These package formats are modern Windows installers and bundles used for multiple architectures. Once policies update, users will not be able to send, receive, open, or download these attachments by default, though admins can whitelist them if required. The change is part of ongoing efforts to reduce exploitation of Office and Windows features that attackers abuse.
read more →

AI-driven infrastructure across lifecycle stages

🤖 Microsoft describes how AI is being applied across the full hardware lifecycle—from design and supply chain to deployment and fleet operations—to accelerate learning and improve decision making. The company emphasizes a “Lean before AI” approach that simplifies processes, builds a governed data foundation, and preserves human judgment. Early results include dramatic reductions in planning cycle time, decreased manual effort, and fewer VM interruptions from disk failures.
read more →

Microsoft named Leader in 2026 Industrial AIoT MQ

🔔 Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Global Industrial AIoT Platforms. The post describes how Azure’s adaptive cloud — including Azure IoT, Azure Arc, Microsoft Fabric, and Microsoft Foundry — connects cloud and edge to turn operational data into actionable intelligence. It emphasizes Industrial and Physical AI to create learning operations that improve productivity, resilience, and safety.
read more →

CISO Views: Managing Vulnerability Risks in AI Age

🔐 This article outlines how frontier AI is changing vulnerability management by producing vastly greater volumes of findings and shifting the CISO challenge from speed to scale and accuracy. It describes Microsoft’s use of AI-powered scanning, harness layers like MDASH, and Red Teaming to find and mitigate flaws, while urging defense-in-depth and Secure by Default controls such as Microsoft Baseline Security Mode (BSM). The post emphasizes coordinated open-source scanning, risk-based decision making, and rolling out secure defaults to reduce exploitation risk.
read more →

Nikkei discloses employee email account breaches

📧 Nikkei reported that attackers accessed two employee email accounts, first a Google Workspace account in late July and later a Microsoft 365 account in September. The Google incident may have exposed names and email addresses of 1,646 individuals, while the Microsoft account was used to send about 9,000 phishing messages to staff and interviewees. Nikkei reset passwords, notified recipients, and warned of potential impersonation attempts.
read more →

Microsoft Exchange privilege escalation advisory

🔒 Microsoft issued out-of-band updates for a high-severity flaw in Microsoft Exchange Server that can allow an authenticated attacker to elevate privileges and access other users' mailboxes within the same organization. Tracked as CVE-2026-96940 with a CVSS score of 8.8, Microsoft applied a service-side fix for Exchange Online, while on-premises customers must install provided updates for specified Exchange Server builds. The company named researcher Jan Mitchell as the reporter and rated exploitability as "Exploitation More Likely."
read more →

Windows KB5124010 causes crashes in AC-3 apps

🎧 Microsoft confirmed that the September 2026 preview update KB5124010 can cause some games and applications using AC-3 (Dolby Digital) audio decoding to crash or close unexpectedly. The update is optional unless devices run Windows 11 24H2 with automatic preview updates enabled. Microsoft noted many modern apps are unaffected because they use alternative decoding, and said it is investigating the issue and will provide further updates when available.
read more →

Warlock ransomware exploits SharePoint to hit critical services

🔒 A China-linked group known as Warlock exploited Microsoft SharePoint vulnerabilities to compromise a water utility, a telecom operator, a regional government, and a university across Portuguese- and Spanish-speaking regions. The actor used web shells, staged the ransomware in SYSVOL to propagate via Group Policy, and disabled protection on dozens of hosts before deploying the ransomware. Symantec and Carbon Black link the activity to Longlegs and provide IoCs and technical details.
read more →

Microsoft warns AI compresses attack timelines

🔍 Microsoft’s 2026 Digital Defense Report warns that AI has allowed threat actors to compress parts of the cyber-attack lifecycle from days to minutes, pressuring defenders to adapt rapidly. The report highlights increased use of agentic models for vulnerability discovery, customized phishing, and bespoke malware, and calls for investment in AI-based defenses and stronger identity controls like phishing-resistant MFA.
read more →

Microsoft: Attackers Leading Early AI Cyber Race

🛡️ Microsoft’s 2026 Digital Defense Report warns that cybercriminals and state-sponsored actors are currently benefiting from AI faster than defenders, accelerating vulnerability discovery, malware creation, and post-compromise operations. The company notes remediation lags discovery, increasing the risk of stockpiled zero-days and rapid weaponization. Microsoft cautions that while defenders will eventually close the gap, organizations face a near-term period of elevated risk and must accelerate their responses.
read more →

Preparing Governments for Interconnected Cyber Risk

🔒 The Microsoft Digital Defense Report finds government agencies were the most impacted sector for cyber threats between July 2025 and June 2026, with 27% of observed activity. The post highlights rising dwell time, increased phishing-driven intrusions, and the expanded risk from compromised credentials. It recommends five priorities for governments, including cross-sector coordination, secure-by-design AI practices, and robust information sharing to strengthen resilience.
read more →

Microsoft: Key Insights from the 2026 Digital Defense Report

🛡️ The 2026 Microsoft Digital Defense Report examines how increasing interconnectedness and advancing AI reshape cyberthreats and defense. It highlights AI’s role in reconnaissance, social engineering, vulnerability discovery, and post-compromise activity while emphasizing that established security fundamentals—identity, least privilege, monitoring, and secure development—remain essential. The report stresses the need to treat AI systems as components within broader environments and to connect signals across systems for better detection and response.
read more →

Microsoft enables Windows settings backup by default

🛠️ Microsoft has enabled the Windows settings backup and restore feature by default for enterprise devices that are Microsoft Entra-joined or hybrid-joined and upgraded to Windows 11 26H2. The tool, originally introduced as an opt-in feature and later made generally available, backs up users' Windows settings and Microsoft Store app lists after device resets, replacements, upgrades, or reimages. The default-on policy applies only where admins have not explicitly configured the setting and excludes devices in DMA-regulated regions, sovereign clouds, or restricted environments. Restore remains admin-controlled and can be managed or disabled via Intune or Group Policy.
read more →

Microsoft Security at Ignite 2026: What to Expect

🔒 Join Microsoft Security at Ignite 2026 in San Francisco or online from November 17–20, 2026, with a Security Pre-Day on November 16. Hear executive keynotes, get hands-on with agentic security solutions, attend expert meetups and MISA partner demos, and participate in sessions across four security themes covering agentic SOCs, securing deployed agents, foundational Zero Trust practices, and data protection.
read more →

Responsible infrastructure and lifecycle of Azure hardware

🔧 Microsoft Azure outlines how it manages the full lifecycle of hyperscale hardware to balance increased compute density with responsible reuse and recycling. The company describes design, operation, secure decommissioning, and repurposing through its global Circular Centers, now expanded to North America, Europe, and Asia Pacific. Azure reports a 92% reuse and recycling rate and highlights automation and AI-driven disassembly to scale circular operations and support Zero Waste goals.
read more →

Microsoft to enforce CSP for Entra ID sign-ins

🔒 Microsoft will begin enforcing stricter Content Security Policy (CSP) protections for Entra ID sign-ins starting mid-October 2026, allowing only scripts from trusted Microsoft CDN domains. The rollout will complete by late October 2026 and aims to block external script injection and cross-site scripting risks during browser-based authentication. Enterprise customers are urged to remove or test browser extensions and code-injection tools to avoid sign-in disruptions. MSAL and API-based flows are not affected because CSP applies only to browser-based sign-ins.
read more →

Monthly security roundup — September 2026

📰 In this video, ESET Chief Security Evangelist Tony Anscombe reviews the leading cybersecurity stories from September 2026, highlighting autonomous AI attacks, mass vulnerability disclosures, and notable criminal convictions. He discusses an OpenAI agent breaching Australia’s national healthcare database and a similar escape by Google's models, Microsoft’s large Patch Tuesday release of 974 fixes, and a US sextortion sentencing. Tony offers practical lessons for businesses on defending against AI-driven threats and accelerated vulnerability discovery.
read more →

Microsoft brings Linux container support to WSL

🐧 Microsoft has made WSL Containers generally available, enabling direct build, run, and deployment of Linux containers on Windows via a new wslc.exe (alias container.exe). The release adds missing preview features like restart, file copy, health checks, networking commands, mounts, and configurable storage. A WSL Containers API lets Windows apps programmatically launch containers, and integrations include Defender for Endpoint, Intune policy controls, and VS Code tooling support.
read more →