< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 11 of 48

Microsoft Exchange Online outage delays emails

📧 Microsoft is addressing a widespread service issue impacting the mail flow pipeline for Exchange Online customers in North America and Germany. Users reported SMTP deferral errors and abrupt connection closures, causing significant delays or failures when sending and receiving email. Engineers are investigating incident EX1331830 to identify root causes and restore normal service.
read more →

Microsoft Build 2026: Agentic Apps with Fabric

🧭 Microsoft highlights how AI-driven agentic workflows demand a shared data context. Microsoft Fabric is presented as a unified data and AI platform that enables developers and agents to build production-ready apps by providing consistent organizational context. New announcements include the open-source Rayfin SDK/CLI for rapid backend deployment and Azure HorizonDB (PostgreSQL-compatible) in public preview, optimized for AI workloads.
read more →

Azure Cobalt 200 VMs Boost Arm AI Workload Performance

🚀 Microsoft announced early access preview of Azure Cobalt 200 Arm-based VMs at Build 2026, delivering up to 50% generational performance improvements over Cobalt 100 for agentic AI and cloud-native Linux workloads. The Cobalt 200 SoC, built on Arm Neoverse V3 and TSMC 3nm, features chiplets, custom accelerators, and enhanced memory and security capabilities. New VM families (including high-memory and dense local storage) expand deployment choices and are available in selected preview regions.
read more →

Managing models, cost, and quality in Foundry

🛠️ Microsoft Foundry presents a unified platform to select, evaluate, optimize, and operate AI models across the full application lifecycle. The post emphasizes that production systems require continuous model selection, validation on real data, cost and latency management, and governance rather than simply picking the most capable model. Foundry adds new model families and Fireworks AI for production-grade open model inference via a single Azure endpoint with enterprise SLAs. It provides model routing, benchmarking with custom datasets, continuous evaluation, and operational controls like versioning, observability, and rollout strategies.
read more →

Foundry IQ: Unified knowledge and serverless retrieval

🔎 Foundry IQ streamlines bringing enterprise and external knowledge into agent workflows by unifying content, improving ingestion, and offering a serverless model for retrieval. The service provides a Model Context Protocol (MCP) server, integrates Microsoft Web IQ for low-latency external context, and includes GA security and compliance features. Serverless Developer tier is in public preview with CU-based billing estimates and scale-to-zero capacity.
read more →

Microsoft threatens researcher after Windows exploits

🔒 An anonymous researcher known as “Nightmare Eclipse” has published several significant exploits targeting Microsoft Windows, including a vulnerability that defeats BitLocker. Microsoft has responded with threats of legal action, prompting public debate and recriminations between the company and security community. The situation has raised concerns about disclosure practices, researcher protections, and the balance between security research and corporate legal responses.
read more →

AI-assisted toolkit used to evade EDR defenses

🔍 Sophos X-Ops uncovered a lab where a threat actor used AI coding tools to develop and test malware aimed at evading EDR products. The files and Git repository showed Python scripts—many partially AI-generated—used to build and iterate evasion modules against vendors including Sophos, CrowdStrike and Microsoft. Humans retained control of the workflow, using AI to accelerate building, testing and refinement while operating inside an AI-native environment.
read more →

Microsoft investigates Office and Teams file access outage

📂 Microsoft is investigating an ongoing incident that prevents some users from opening files in Office for the web and Microsoft Teams. Impacted apps include Excel and PowerPoint for the web, with affected users seeing an error stating "Office Online services aren't available right now." The company is analyzing service telemetry and has identified a potential cross-service issue while it works toward remediation.
read more →

Critical Windows Netlogon RCE Flaw Now Exploited

🔒 The Centre for Cybersecurity Belgium (CCB) warned that threat actors are exploiting a recently patched critical Windows Netlogon vulnerability (CVE-2026-41089). Microsoft patched the stack-based buffer overflow during May 2026 Patch Tuesday, which can allow unauthenticated remote code execution on domain controllers. The CCB urged administrators to apply updates immediately, noting a CVSS score of 9.8, while Microsoft has not yet confirmed active exploitation.
read more →

Microsoft resolves outage impacting MFA setup access

🔧 Microsoft confirmed and mitigated an incident that prevented some users from setting up multi-factor authentication and accessing the My Sign-Ins site, where affected users encountered 504 Gateway Timeout errors. The company failed over to alternate infrastructure and monitored telemetry while evaluating further mitigations. Microsoft later restored the service, attributing the outage to a cache configuration change that caused high CPU and memory load during an EU traffic peak.
read more →

Microsoft fixes Windows 11 KB5089549 install failures

🔧 Microsoft has fixed a known issue that caused installation failures and 0x800f0922 errors for the May 2026 Windows 11 security update (KB5089549). The failures were triggered by insufficient free space on the EFI System Partition (ESP), causing updates to rollback during reboot at roughly 35–36% completion. The fix is included in the May 26, 2026 preview cumulative update (KB5089573) and will be made available broadly in the June Patch Tuesday updates, with mitigation options for enterprises via Known Issue Rollback or Group Policy.
read more →

Microsoft and researcher clash over disclosure rules

🛡️ Microsoft and a prominent researcher publicly traded barbs after the researcher, going by Nightmare Eclipse, published vulnerabilities he said were ignored; Microsoft countered that those disclosures were irresponsible and increased risk. The exchange included personal accusations, account deletions, and threats, prompting discussion within the security community about disclosure practices. Senior Microsoft staff signaled a review of processes while defenders on both sides highlighted valid concerns about communication, prioritization, and trust.
read more →

Microsoft named Leader in 2026 Endpoint Protection

🛡️ For the seventh consecutive time, Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection, reflecting customer trust in Microsoft Defender. Defender provides industry-leading EDR backed by global threat intelligence and connects endpoints, identities, email, apps, cloud, and data to enable earlier detection and stronger prevention. Recent advancements include proactive attack disruption, custom telemetry, simplified onboarding, sovereign-ready protection, and agentic endpoint security for local AI agents.
read more →

Claude Opus 4.8 Now Available in Microsoft Foundry

🚀 Claude Opus 4.8 is now accessible in Microsoft Foundry, providing developers and enterprises with Anthropic’s most capable Opus model for coding, agentic tasks, and professional work. The update focuses on long-running workflows, deeper reasoning across documents and codebases, and more reliable tool use for multi-step automation. Teams can now evaluate and deploy the model within Foundry’s unified platform for building and operating AI applications.
read more →

Analysis of The Gentlemen self‑propagating ransomware

🛡️ This Microsoft Threat Intelligence blog dissects The Gentlemen, a Go-based RaaS that combines per-file ephemeral Curve25519/XChaCha20 encryption with aggressive self-propagation across networks. The post details operator models, command-line controls, speed modes, privilege elevation via scheduled tasks, and extensive defense-evasion steps including disabling Defender, deleting shadow copies, clearing logs, and terminating backup, database, virtualization, and EDR services. Practical mitigations, Defender detections, hunting queries, and IOCs are provided for defenders and incident responders.
read more →

Amazon WorkSpaces BYOL for Windows Desktop OS

🖥️ Amazon WorkSpaces Applications now supports Bring Your Own License (BYOL) for Windows Desktop operating systems, enabling customers to stream Microsoft 365 Apps for enterprise and full desktop experiences on hardware dedicated to their AWS account. Organizations can reduce costs by avoiding OS fees and maintain a consistent user experience between local and streamed environments. Availability spans multiple AWS Regions and requires meeting Microsoft licensing rules plus minimum monthly streaming commitments.
read more →

Microsoft Rebukes Public Zero‑Day Disclosures

🛡️ Microsoft has urged the security research community to follow Coordinated Vulnerability Disclosure (CVD) after a researcher publicly released details and exploit code for multiple Windows zero‑days, including issues in Defender and BitLocker. The company said several disclosed flaws were not shared with Microsoft before publication, exposing customers to unnecessary risk and prompting security teams to work continuously on protections and updates. Some of the disclosed flaws — BlueHammer, RedSun and UnDefend — are reported to be actively exploited in the wild, and vendor actions have included takedowns of the researcher’s GitHub account.
read more →

Microsoft criticizes uncoordinated zero-day disclosures

🛡️ Microsoft has criticized researchers for publicly disclosing six zero-day vulnerabilities before patches were available, calling such actions irresponsible and risky. The company said its security teams are working around the clock to investigate and mitigate issues including privilege escalation and bypass flaws in Defender and BitLocker. Microsoft urged adherence to industry-standard coordinated vulnerability disclosure (CVD) practices, typically allowing a 90-day embargo for patch development. It cautioned that uncoordinated releases can place proof-of-concept exploit code into malicious hands and undermines efforts to protect customers.
read more →

GPU-mining campaign uses SEO and AI for delivery

🛡️ Microsoft uncovered a targeted cryptojacking campaign that lures owners of high-performance PCs to malicious download pages for utilities like CrystalDiskInfo and HWMonitor. The attackers used SEO poisoning and, in some cases, manipulated AI chatbots to surface attacker-controlled download links. Infected ZIP archives include legitimate utilities and a malicious DLL that installs the ScreenConnect remote access tool, enabling persistent access and deployment of a process-hollowing loader that ultimately launches GPU miners.
read more →

Windows 11 KB5089573 preview brings performance fixes

🔧 Microsoft released the KB5089573 preview cumulative update for Windows 11 25H2 and 24H2, delivering 30 non-security changes focused on performance and reliability. The optional May 2026 update accelerates app launch and core shell experiences (Start, Search, Action Center) and improves Windows Hello sign-in behavior and reliability. It also addresses File Explorer stability, touch gestures, Modern Standby resume performance, and reduces authentication blocks for Windows Hello Enhanced Sign-in Security. Devices upgrade to builds 26200.8524 and 26100.8524 and updated Secure Boot certificates are being phased in ahead of expiring 2011 certificates.
read more →