< ciso
brief />
Tag Banner

All news with #microsoft tag

1056 articles · page 11 of 53

Microsoft‑signed UEFI shims allow Secure Boot bypass

🛡️ ESET found 11 Microsoft-signed UEFI shim bootloaders (version 0.9 or earlier) contain vulnerabilities that enable Secure Boot bypass across many systems. These shims trust outdated second-stage loaders like older GRUB 2 builds, allowing unsigned kernels or bootkits to load even with Secure Boot enabled. Microsoft issued dbx revocations on June 9; Windows will update automatically and Linux users should fetch revocations via the Linux Vendor Firmware Service. ESET cautions defenders to follow protection guidance rather than rely on IoCs.
read more →

CISA warns: patch actively exploited SharePoint flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) in Internet-exposed on-premises instances. The flaws enable authentication bypass, remote code execution, and post-exploitation activity including theft of IIS machine keys and persistence to deploy malware. CISA urged administrators to apply Microsoft's patches, verify installation, shorten patch cycles, enable AMSI integration for SharePoint, use Microsoft Defender Antivirus detections, and implement hardening and monitoring measures.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

Microsoft blocks update for Dell devices after shutdowns

🛠️ Microsoft is blocking the June Windows 11 update on some Dell systems after the KB5095093 preview update introduced an incompatibility with the Intel Innovation Platform Framework Processor Participant driver. Affected devices may show a yellow exclamation in Device Manager and experience unexpected shutdowns, poor performance, overheating, and battery drain. Microsoft is working with Dell and will pause KB5101650 distribution until a fix is released in the coming days.
read more →

Microsoft July 2026 Patch Tuesday: 622 Flaws Released

🛡️ Microsoft released its July 2026 security updates addressing 622 vulnerabilities across many products, including 57 marked critical. Two flaws have confirmed in-the-wild exploitation: an AD FS elevation of privilege (CVE-2026-56155) and a SharePoint spoofing/authentication issue (CVE-2026-56164). Talos highlights multiple critical remote-code-execution and elevation-of-privilege flaws affecting Windows components, Office, SharePoint, SQL Server, Defender, Copilot and cloud services. Cisco Talos also published Snort rules and urged customers to update intrusion-detection rule sets to detect exploitation attempts.
read more →

Microsoft ships record July Patch Tuesday fixes

🔒 Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs including two actively exploited elevation-of-privilege flaws in on‑premises SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint bug allows unauthenticated network privilege escalation and is tied to incident responders at Mandiant and Google's FLARE; admins should patch immediately and consider enabling AMSI Full Mode. The AD FS bug permits local privilege escalation for authenticated users and was credited to Microsoft DART. A third disclosed BitLocker bypass (CVE-2026-50661) requires physical access and is lower priority. The update also finalizes Kerberos RC4 hardening, risking authentication breaks for service accounts still using RC4 unless audited and rotated first. Microsoft says AI tooling increased bug discovery, and the scale of fixes means organizations should prioritize by exploitation status rather than CVSS score.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Microsoft issues Windows 10 KB5099539 security update

🔒 Microsoft released the Windows 10 KB5099539 extended security update, delivering the July 2026 Patch Tuesday fixes and additional security and reliability improvements for enrolled devices and LTSC editions. The update moves Windows 10 to build 19045.7548 (19044.7548 for Enterprise LTSC 2021) and addresses a record 570 vulnerabilities, including two exploited and one publicly disclosed zero-day. Administrators and eligible consumers can install it via Settings > Windows Update; several known issues and hardening changes are documented.
read more →

Windows 11 July 2026 Cumulative Updates Released

🛈 Microsoft released Windows 11 cumulative updates KB5101650 and KB5099414 for 25H2/24H2 and 23H2 to deliver July 2026 Patch Tuesday fixes addressing security vulnerabilities, bug fixes, and feature refinements. The rollouts update build numbers and include notable Bluetooth pairing improvements, a quieter Widgets experience, enhanced accessibility controls, File Explorer and networking fixes, and Point-in-Time restore availability. Install via Settings > Windows Update or the Microsoft Update Catalog.
read more →

Old Microsoft-signed UEFI shims expose Secure Boot

🔒 Researchers found 11 Microsoft-signed UEFI shim bootloaders that can be abused to bypass Secure Boot on many systems, enabling execution of untrusted code during early boot. ESET and CERT/CC detail how outdated shims (mostly v0.9 and earlier) remained trusted because they were not revoked, allowing attackers to deploy UEFI bootkits and persist below the OS. Microsoft revoked affected certificates in June 2026 following disclosures.
read more →

Microsoft trials cleaner, ad-free Windows Search

🔍 Microsoft is testing a faster, cleaner Windows Search experience for Insiders that emphasizes relevant local results over ads and promotional content. The update, announced by Windows search leads, is rolling out via the Experimental channel and Controlled Feature Rollout, with feature flags and a reboot check for access. Changes include clearer result sources, a setting to hide Store and web suggestions, improved two-character file search, better cloud-file visibility, and increased typo tolerance. Reliability fixes and additional improvements are coming soon.
read more →

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →

ModHeader removed after hidden browsing-history collector

🛡️ Google and Microsoft removed the popular ModHeader extension after researchers found a dormant browsing-history collector embedded in the official store builds. The collector, confirmed by Stripe OLT to be in the genuine Chrome package, stored encrypted domain lists and device fingerprints locally and was designed to upload them to api.stanfordstudies[.]com on a schedule if an internal allow-list were populated. While the allow-list shipped empty and no evidence shows data was exfiltrated, the extension still pinged extensions-hub[.]com and logged request metadata locally. Users are advised to uninstall ModHeader, rotate exposed secrets, and defenders should block the implicated domains and hunt for related indicators.
read more →

Microsoft makes passkeys default for Entra ID

🔒 Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more →

Microsoft Secure Future Initiative July 2026 Report

🔒 This progress report outlines Microsoft’s Secure Future Initiative (SFI) two-year effort to strengthen security foundations, apply AI for proactive defense, and prepare for future challenges such as post-quantum risks. It highlights layered controls—identity, access governance, segmentation, and secure engineering defaults—paired with cultural and governance measures to make protections durable. The report also shares lessons, practical guidance, and metrics of organizational adoption.
read more →

GigaWiper: Unified backdoor blends espionage and wiping

🛡️ Microsoft has identified GigaWiper, a versatile Golang backdoor that consolidates espionage and multiple destructive wiping capabilities into a single implant. The tool merges components from at least three prior malware families, enabling command-and-control, disk-level wiping, fake ransomware with unrecoverable keys, and multi-pass secure wiping. Researchers observed standalone wipers and larger backdoor binaries, and advise enabling tamper protection, cloud-delivered antivirus, EDR in block mode, and blocking known C2 infrastructure.
read more →

Microsoft warns of rising Windows security updates

🛡️ Microsoft says it is deploying AI-driven analysis to uncover more zero-day vulnerabilities across the Windows codebase, warning customers to expect an increased number of security updates. The company described a multi-model agentic scanning harness (MDASH) and a separate prove pipeline to validate findings, aiming to reduce false positives and shorten review windows. Microsoft also plans to update its Secure Development Lifecycle to address AI-enabled attack techniques while retaining human oversight to ensure update quality.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →