< ciso
brief />
Tag Banner

All news with #microsoft tag

1056 articles · page 10 of 53

Invisible PR comment lets Azure DevOps AI abuse access

🛡️ A hidden HTML comment in an Azure DevOps pull request can instruct a reviewer's AI coding agent to act beyond an attacker's privileges, leaking sensitive data. The flaw exists because the MCP server returns PR descriptions without the spotlighting guardrail applied elsewhere, so the agent receives hidden instructions the human reviewer cannot see. Manifold Security demonstrated a proof-of-concept that chains permitted agent calls to read cross-project resources and exfiltrate content using reviewer credentials. Microsoft acknowledged the report and recommended limiting project access and reviewing changes before running AI tools.
read more →

Critical SharePoint RCE Exploited to Steal Machine Keys

🔒 Microsoft SharePoint's critical CVE-2026-50522 vulnerability is being actively exploited in the wild to steal machine keys and preserve access post-patch. Researchers observed attackers leveraging a public proof-of-concept to trigger deserialization-based remote code execution against on-premises SharePoint, allowing creation of forged authentication tokens. Microsoft fixed the flaw in July, but security firms advise rotating exposed credentials and confirming patches.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation

🛡️ Microsoft patched a critical SharePoint Server deserialization flaw, CVE-2026-50522 (CVSS 9.8), which is now being actively exploited. DEVCORE researcher splitline reported the issue; Microsoft warned authenticated attackers with Site Owner privileges could execute remote code. Security firms and CISA observed attackers stealing machine keys and urged credential rotation even after patching.
read more →

Microsoft issues WSUS sync fix and manual mitigation

🛠️ Microsoft published manual steps to remediate a WSUS synchronization problem that causes Windows Update scans to fail or time out on affected servers. The issue affects client (Windows 10, v1607+) and server (Windows Server 2012+) platforms and leads to prolonged sync times or operation timeouts due to accumulating publishing metadata. A service-side mitigation was rolled out for new or rebuilt WSUS installations, while administrators with existing servers are advised to back up SUSDB, run cleanup SQL queries, reset MaxXMLPerRequest, reindex SUSDB, run the WSUS Server Cleanup Wizard, and restart IIS or the WsusPool to restore normal sync behavior.
read more →

Unofficial patches available for LegacyHive zero-day

🛡️ Free unofficial micropatches are available for a recently disclosed Windows zero-day, dubbed LegacyHive, which enables non-admin users to escalate privileges by mounting other users' registry hives. The vulnerability was disclosed by researcher Nightmare Eclipse alongside a stripped proof-of-concept after Microsoft's July 2026 updates. ACROS Security (0Patch) offers free micropatches for affected Windows 10 2004+/Windows Server 2022+ systems; Microsoft says it is investigating the claims.
read more →

OneDrive and Google Drive for Multi‑Session Fleets

📂 Amazon WorkSpaces Applications now supports Microsoft OneDrive for Business and Google Drive as persistent storage options for multi-session fleets. Users streaming on shared fleet instances can connect their cloud accounts to access, save, and sync files directly within sessions, alongside the existing S3-backed home folder. This feature is available in all AWS Regions where WorkSpaces Applications is offered and incurs no extra charge beyond standard streaming usage pricing.
read more →

HollowGraph: Malware Using Microsoft 365 Calendar C2

🛡️ Group-IB discovered a .NET espionage implant called HollowGraph that uses a hijacked Microsoft 365 calendar as a covert command-and-control channel, reading operator instructions from a calendar event dated 2050-05-13 and exfiltrating stolen files as attachments. The implant uses the Microsoft Graph API to blend with legitimate traffic and avoids contacting attacker-owned servers directly. A secondary DNS-based channel supplies Entra ID client credentials via IPv6 AAAA records, written to a log file named logAzure.txt. Group-IB links the malware to the Cavern code family and recommends monitoring calendar events, application-driven Graph activity, and suspicious DNS AAAA queries.
read more →

Microsoft works to resolve WSUS sync delays

🛠️ Microsoft is addressing a known issue that has caused Windows Server Update Services (WSUS) servers to experience prolonged synchronization times and timeouts, impacting the delivery of updates. The problem, with heightened impact since July 13, 2026, affects client and server platforms and prevents admins from deploying updates through WSUS or Configuration Manager. Mitigations have been deployed for new or rebuilt WSUS installations, and Microsoft is developing additional steps to remediate previously affected servers.
read more →

Microsoft issues emergency fix for Dell shutdown bug

🛠️ Microsoft released out-of-band updates to address a compatibility issue that caused some Dell PCs to shut down or suffer performance and power problems after July 2026 Windows 11 updates. The bug stems from a June preview change to the Windows USB-C Connection Manager that conflicts with the Intel Innovation Platform Framework (IPF) Processor Participant driver, producing a yellow exclamation in Device Manager. Microsoft blocked the July update on affected systems and on Saturday shipped emergency updates KB5121767 and KB5121768 for Windows 11 25H2, 24H2 and Enterprise LTSC 2024 to resolve the issue. Managed devices with Autopatch will get the fix automatically, while Intune admins can accelerate deployment; affected users should restart after installation.
read more →

Microsoft warns of surge in ACR Stealer attacks

🛡️ Microsoft reports a marked increase in attacks leveraging ACR Stealer, an info-stealing MaaS that exfiltrates browser passwords, tokens, and sensitive documents from enterprise environments. Between late April and mid‑June, threat actors used social engineering (ClickFix), WebDAV servers, and mshta.exe to deliver obfuscated PowerShell loaders, Python-based installers, and in-memory payloads. The actor abuses GUID-based WebDAV paths, steganographic JPEGs, and public blockchains as dead-drop resolvers to mask activity and maintain C2 communications. Microsoft recommends filters, application control, and limiting access to unnecessary web resources to reduce exposure.
read more →

Microsoft at Black Hat USA 2026: Defending Trust

🔒 At Black Hat USA 2026, Microsoft Security highlights how threat actors exploit trusted systems—software, developer workflows, identities, and AI—to scale attacks. Sessions and briefings across August 4–6 focus on supply chain compromises, AI security, and practical defense strategies. Visit booth #2144 for demonstrations, expert-led services, and community events including a reception on August 5.
read more →

New LegacyHive Windows zero-day enables privilege escalation

🔒 A researcher known as Nightmare Eclipse published a proof-of-concept named LegacyHive after Microsoft's July 2026 Patch Tuesday, claiming it exploits a vulnerability in the Windows User Profile Service. The PoC has been intentionally modified to require additional credentials, making exploitation harder than earlier releases. Analysts note successful exploitation allows non-admin users to modify the classes registry hive and achieve code execution on admin login. Detection queries for Microsoft Defender for Endpoint were published shortly after.
read more →

Windows Server 2022 to leave mainstream support in 2026

📰 Microsoft has announced that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, and will transition to extended support with security updates through October 14, 2031. Customers are advised to plan upgrades to Windows Server 2025, the latest LTSC release available since November 2024. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and highlighted lifecycle resources for planning migrations.
read more →

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

CISA urges immediate SharePoint hardening now

🔒 CISA has warned that three Microsoft SharePoint vulnerabilities are being actively exploited and urged organizations to immediately patch on-premises SharePoint deployments. Administrators should follow Microsoft’s mitigation guidance, enable AMSI integration, hunt for indicators of compromise, and rotate machine keys where appropriate. The agency added CVE-2026-33201, CVE-2026-45659, and the newly listed CVE-2026-56164 to its Known Exploited Vulnerabilities catalog and required rapid remediation for federal agencies.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft announced that Windows 11 version 24H2 Home and Pro editions and Windows 10 Enterprise LTSB 2016 will stop receiving monthly updates after October 13, 2026. Enterprise and Education editions remain supported until October 12, 2027. Users are advised to upgrade to Windows 11 25H2, which is available via an enablement package and will be offered automatically to unmanaged Home and Pro devices. Devices can defer the update or choose restart timing through Settings > Windows Update.
read more →

Microsoft July 2026 Patch Tuesday: 570+ Vulnerabilities

🔒 July’s Patch Tuesday from Microsoft addressed an unprecedented number of vulnerabilities, with reports of 570–622 CVEs (620 if platform-level fixes are counted), plus hundreds in Chromium. The release includes many high-severity flaws — notably elevation of privilege and remote code execution bugs — with only three zero-days and 59 critical issues. Microsoft’s new summary-style advisories and its AI-powered MDASH scanning explain the surge, forcing organizations to reassess patch management and prioritization.
read more →

Defender Experts Close the Intelligence‑to‑Action Gap

🛡️ Microsoft announces Defender Experts Threat Intelligence and expands Defender Experts MDR to include third-party and multi-cloud coverage. The expert-led services translate global signals into prioritized, environment-specific guidance and integrate Microsoft Defender Threat Intelligence into the Defender portal for real-time use across detection, investigation, response, and hunting. Defender Experts MDR Plan 2 extends managed detection and response beyond Microsoft products using Microsoft Sentinel, enabling experts to follow threats across heterogeneous estates. These offerings aim to shorten the time from signal to decisive action and will be showcased at Black Hat.
read more →