< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 17 of 48

Microsoft to Deploy Entra Passkeys on Windows in Late April

🔐 Microsoft will roll out Entra passkey support for phishing‑resistant passwordless authentication on Windows devices starting in late April, with general availability expected by mid‑June 2026. The capability enables device‑bound FIDO2 passkeys stored in the Windows Hello container and used via face, fingerprint, or PIN on corporate, personal, and shared devices, including unmanaged Windows machines. Administrators can control rollout and access through Conditional Access and Authentication Methods policies.
read more →

Admins Can Now Uninstall Copilot from Windows 11 Enterprise

🛠️ Microsoft now allows IT administrators to uninstall the AI-powered Microsoft Copilot app from managed enterprise devices using the new RemoveMicrosoftCopilotApp policy setting, broadly available after the April 2026 Patch Tuesday. The setting is provided as a Policy CSP and Group Policy for endpoints managed via Microsoft Intune or SCCM, and applies only to Windows 11 25H2 devices where both Microsoft 365 Copilot and Microsoft Copilot are installed, the user did not install the Copilot app, and it has not been launched in the last 28 days. If enabled, the app will be uninstalled in a non-disruptive way; users can still re-install it if they choose.
read more →

OpenAI GPT-5.5 in Microsoft Foundry for Enterprise Use

🚀 GPT-5.5 is being made generally available in Microsoft Foundry, enabling enterprises to run OpenAI's latest frontier model for production agentic workflows. The model brings deeper long-context reasoning, improved agentic execution, higher computer-use accuracy, and better token efficiency. Foundry supplies governance, identity isolation, persistent sandboxes, and integrations to evaluate and scale agents securely.
read more →

Amazon Quick Adds Document-Level SharePoint ACLs Support

🔒 Amazon Quick now supports document-level access controls (ACLs) for Microsoft SharePoint knowledge bases, allowing organizations to preserve native SharePoint permissions when indexing content. Quick uses a dual approach—ACL replication for fast pre-retrieval filtering paired with real-time permission checks against SharePoint at query time—to avoid stale or incorrectly mapped access. Administrators can enable this in an admin-managed SharePoint knowledge base in the Quick console; the feature is available in all Regions where Quick is offered.
read more →

UNC6692: Social Engineering and Custom SNOW Malware

🔒 UNC6692 used persistent social engineering to lure victims via Microsoft Teams, delivering a staged payload that installed an AutoHotkey loader and a malicious Chromium extension (SNOWBELT) from attacker-controlled AWS S3. The intruders deployed a modular suite — SNOWBELT, SNOWGLAZE, and SNOWBASIN — to establish WebSocket tunnels, local HTTP backdoors, and stealthy proxying for lateral movement. The campaign combined credential theft, LSASS and NTDS extraction, and exfiltration to cloud services, highlighting the need to monitor browser extensions and cloud egress.
read more →

Microsoft: Edge update prevents some Teams meeting joins

⚠️ Microsoft confirmed a recent Microsoft Edge update introduced a regression preventing some Windows users from joining scheduled Microsoft Teams meetings or meetings launched via links. The company advised impacted users to restart the Teams client as a temporary workaround while engineers analyze diagnostic data and monitor recent service changes. Microsoft classified the incident as an advisory and has not disclosed affected regions or user counts.
read more →

GopherWhisper APT Abuses Outlook, Slack, Discord in Attacks

🔐 A previously undocumented state-linked threat cluster dubbed GopherWhisper has been observed using a Go-based toolkit and legitimate services such as Microsoft 365 Outlook (via the Microsoft Graph API), Slack, and Discord to perform command-and-control and payload delivery. ESET identified the campaign targeting a Mongolian government entity and uncovered multiple backdoors — including LaxGopher, RatGopher, and BoxOfFriends — plus an exfiltration utility that uploads stolen archives to file.io. Analysts recovered thousands of Slack and Discord messages from attacker accounts, and telemetry including UTC+8 activity helped link the group to China.
read more →

CISA Orders Patching of Microsoft Defender BlueHammer Flaw

🔒 CISA has ordered federal agencies to urgently patch a high-severity Microsoft Defender privilege escalation vulnerability tracked as CVE-2026-33825 and publicly dubbed BlueHammer, after evidence of active exploitation. Microsoft released a patch on April 14 following public disclosure and proof-of-concept code published by a researcher using the handle 'Chaotic Eclipse', who also revealed related Defender issues. Huntress Labs reported attacks showing hands‑on‑keyboard activity and suspicious FortiGate SSL VPN access tied to a Russia‑geolocated IP. Agencies must apply mitigations or update systems within two weeks, with a compliance deadline of May 7.
read more →

Microsoft Adds Anthropic Mythos to SDLC, Boosts Security

🔒 Microsoft will integrate Anthropic’s Mythos Preview into its Security Development Lifecycle, using the model alongside other advanced AI to surface vulnerabilities earlier in the software development process. The company says the move aims to strengthen and harden core products including Windows, Azure, and Microsoft 365 by improving automated detection and secure coding. Analysts note the shift signals frontier models moving from experimental tools into standard engineering workflows while raising dual-use concerns.
read more →

Microsoft issues out-of-band patch for ASP.NET Core flaw

🔒 Microsoft released an out-of-band fix after an April 14 .NET update (10.0.6) introduced a critical regression in the ASP.NET Core Data Protection NuGet package (CVE-2026-40372, CVSS 9.1). A bug in the ManagedAuthenticatedEncryptor caused HMAC validation tags to be computed with an incorrect offset, allowing forged cookies and tokens to be treated as valid. Developers should upgrade to 10.0.7, rebuild embedded apps (including Docker images), expire affected cookies and tokens, and rotate protection keys to remove potential forgeries.
read more →

AI-Powered Defense for an AI-Accelerated Threat Landscape

🛡️ Microsoft outlines how defenders can harness AI to counter an accelerating threat environment. Through Project Glasswing and partnerships with model providers such as Anthropic, Microsoft tested Claude Mythos Preview against the CTI-REALM benchmark and observed meaningful detection improvements. The company plans to integrate advanced models into its Security Development Lifecycle, deploy rapid Defender detections, and share protections through MSRC and MAPP. The Secure Now exposure-management experience is available today, and a multi-model scanning harness is expected in preview in June 2026.
read more →

Microsoft Discovery: Agentic R&D at Enterprise Scale

🔬 Microsoft Discovery is an extensible platform that brings agentic orchestration, advanced reasoning, a graph-based knowledge foundation, and high-performance computing to enterprise R&D. It equips specialized agents to reason across proprietary data and external literature, generate hypotheses, and validate them through simulation and lab integrations under centralized governance. Built on Azure, the platform emphasizes security, compliance, partner interoperability, and enterprise-grade controls while remaining in preview.
read more →

Microsoft Teams adds Efficiency Mode for low-resource PCs

⚙️ Microsoft is rolling out an Efficiency Mode for Teams on Windows and Mac to improve responsiveness on devices with constrained CPU and memory. Enabled by default on eligible systems, the mode dynamically reduces camera resolution during meetings, launches the app without a pre-selected chat, and displays a static image in the message pane. The change begins in early May 2026 and will complete by mid-May. Users can opt out via Settings > General by toggling on "Never use efficiency mode," and Teams will display an indicator when the mode is active.
read more →

CISA Adds One Vulnerability to KEV Catalog After Exploitation

⚠ CISA has added one vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-33825, an Microsoft Defender access-control issue characterized by insufficient granularity and identified as being actively exploited. The agency emphasizes that this class of flaw is a frequent attack vector and presents significant risk to the federal enterprise. Under BOD 22-01, Federal Civilian Executive Branch agencies must remediate KEV entries by the prescribed due date, and CISA strongly urges all organizations to prioritize timely remediation as part of routine vulnerability management.
read more →

Microsoft Graph API Bug Disrupts Universal Print Shares

⚠️ Microsoft has traced an ongoing Universal Print sharing failure to a code change in the Microsoft Graph API, which increased Entra ID directory replication latency and exposed a pre-existing race condition that causes intermittent “Sharing Print Failed” errors when creating certain printer shares. The issue (UP1287359) affects shares created with the "Allow all users in my organization" toggle or when specific users/groups are selected. Microsoft is deploying a corrective code change and published a 13-step workaround that involves creating the share without assigning members initially, waiting for propagation, and then adding users or security groups manually.
read more →

Microsoft Issues Patch for Critical ASP.NET Core Flaw

🔒 Microsoft released an out-of-band update to address a high-severity privilege-escalation flaw in ASP.NET Core tracked as CVE-2026-40372 (CVSS 9.1). A regression in Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 allowed the managed encryptor to compute HMAC validation over incorrect payload bytes, enabling forged payloads to pass authenticity checks and potentially grant SYSTEM-level access on non-Windows hosts. Microsoft fixed the issue in ASP.NET Core 10.0.7 and warned tokens issued during the vulnerable window remain valid until the DataProtection key ring is rotated.
read more →

Microsoft issues emergency patches for ASP.NET flaw

🔒 Microsoft has released out-of-band updates to fix a critical ASP.NET Core privilege escalation vulnerability (CVE-2026-40372) in the ASP.NET Core Data Protection APIs. A regression in the Microsoft.AspNetCore.DataProtection 10.0.0–10.0.6 packages caused HMAC validation to be computed over the wrong bytes, allowing forged auth cookies and decryption of protected payloads. Developers should update to 10.0.7, redeploy, and rotate DataProtection key rings to invalidate tokens issued during the vulnerable window.
read more →

Azure Accelerate for Databases: Modernize Data for AI

🚀 Azure Accelerate for Databases is a Microsoft program that helps organizations modernize database estates to become AI-ready. It bundles a Savings Plan (up to 35% vs. pay-as-you-go), delivery funding, Azure credits, zero-cost Cloud Accelerate Factory support, partner services, AI-enhanced assessments, and role-based skilling. The offering aims to reduce friction and speed migrations at scale. Microsoft highlights Thomson Reuters’ migration of over 18,000 databases as a customer example.
read more →

State-Sponsored & Phishing Trends: Printers, M365 Risks

🔍 This podcast episode examines the 2025 Talos Year in Review, highlighting a sharp increase in internal phishing that evades traditional perimeter defenses. Hosts Amy Ciminnisi and Martin Lee explain how Microsoft 365's Direct Send feature has been broadly weaponized to deliver trusted-looking internal mail. They also unpack blended state-sponsored campaigns from China and North Korea that pair zero-day exploitation with advanced social engineering.
read more →

Phishing and MFA Exploitation: Targeting Trust in Workflows

🔐 In 2025 attackers increased focus on weaknesses in multi-factor authentication (MFA) and the trust inherent in everyday workflows, with phishing used for initial access in 40% of incidents. Cascaded phishing leveraged compromised, legitimate accounts to craft highly convincing lures, while abuse of Microsoft 365 Direct Send enabled internal-looking spoofed messages. MFA spray attacks and device compromise—driven by voice phishing against administrators—targeted IAM tools and high-turnover device ecosystems, with higher education notably impacted. Defenders should harden device management, enforce strong lockout and conditional access policies, and adopt email protections such as Reject Direct Send and tightened SPF/DMARC.
read more →