< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 20 of 48

Microsoft Suspends Dev Accounts for Open-Source Projects

⚠️ Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects, blocking them from publishing Windows builds and security patches without prior notice or a quick reinstatement path. Affected projects include WireGuard, VeraCrypt, MemTest86, and Windscribe. Maintainers report no emails, warnings, or clear appeals process and say they can still publish Linux and macOS updates but not Windows releases. Microsoft said accounts were automatically suspended for failing mandatory verification for the Windows Hardware Program and that outreach and press attention have prompted follow-up from company representatives.
read more →

Microsoft Agent Governance Toolkit Addresses OWASP AI Risks

🛡️ Microsoft has released the open-source Agent Governance Toolkit to monitor and control AI agents during runtime as organizations move them into production. The toolkit enforces policies aligned with OWASP top risks for agentic systems, such as prompt injection, identity abuse, and tool misuse, while improving visibility across multi-step workflows. It ships as multi-language components and integrates with existing frameworks like LangChain without requiring agent rewrites. The project is in public preview under an MIT license.
read more →

Microsoft rolls out fix for broken Windows Start search

🔧 Microsoft has deployed a server-side fix after a Bing update disrupted Windows 11 23H2 Start Menu search on a small number of devices. The issue, first noted around April 6 and reportedly seen by some users for months, produced blank but clickable search results. Microsoft rolled back the problematic server-side Bing update and says reports of failures are decreasing; the company advises ensuring the device is online and that Web Search has not been disabled by Group Policy.
read more →

Storm-1175 (Medusa) Accelerates Ransomware Attacks

⚠️ Microsoft warns that Storm-1175 — an actor linked to Medusa ransomware — is rapidly exploiting internet-facing systems, often moving from initial access to data theft and encryption within 24 hours. The group has abused more than 16 vulnerabilities since 2023, including zero-days, and frequently chains exploits to establish persistence and accelerate operations. Targets include healthcare, education, professional services, and finance in Australia, the UK and the US.
read more →

Microsoft fixes Classic Outlook email delivery bug

🛠️ Microsoft implemented a server-side fix to resolve a known issue that prevented some Classic Outlook users from sending messages via Outlook.com. Affected users received non-delivery reports (NDRs) showing error codes such as 0x80070005-0x0004dc-0x000524 and a warning that messages could not be sent. The Outlook Team says the change was deployed to production on April 3, 2026. If problems persist, Microsoft recommends using the New Outlook client or Outlook on the web and provides a temporary workaround to download the Outlook Address Book for impacted accounts.
read more →

Microsoft Removes SaRA Tool from Supported Windows

🛠️ Microsoft has deprecated and removed the Support and Recovery Assistant (SaRA) command‑line utility from all in‑support Windows updates effective March 10. The company recommends administrators migrate to the Get Help command‑line tool (GetHelpCmd.exe), which offers similar diagnostic capabilities and runs on a more secure infrastructure. Get Help can be scripted and executed remotely to troubleshoot Microsoft 365 apps, Outlook, Teams, and Windows clients.
read more →

Microsoft Continues Fixes for Exchange Online Access Issues

🔧 Microsoft is investigating intermittent Exchange Online mailbox access problems that have affected users of the Outlook mobile apps and the new Outlook for Mac client for several weeks. The issue was initially tracked as EX1256020 and marked resolved on April 1, but was re‑added under EX1268771 after tenants reported ongoing impact. Microsoft says it is restarting the Notification Broker service on affected infrastructure while continuing root‑cause analysis and deploying additional mitigations to prevent recurrence.
read more →

Microsoft forces upgrade of unmanaged Windows 11 24H2

🔁 Microsoft has begun force-upgrading unmanaged devices running Windows 11 24H2 Home and Pro editions to Windows 11 25H2. The company says its machine-learning-based intelligent rollout now targets all Home and Pro 24H2 systems not managed by IT, and those devices will stop receiving fixes, time zone updates, technical support, and monthly security updates once 24H2 reaches end of support on October 13, 2026. Users can manually check for the 25H2 update in Settings > Windows Update, pause updates temporarily, or follow Microsoft's support guidance if issues occur.
read more →

AI-Enabled Attacks Transform Cyber Threat Operations

🤖 Microsoft describes a shift from AI as a tool to AI as an embedded attack surface, accelerating tempo, precision, and scale across reconnaissance, malware development, and post-compromise activity. AI-enhanced phishing campaigns now report click-through rates near 54% versus roughly 12% for traditional campaigns, a 450% increase. The blog highlights Tycoon2FA, tied to Storm-1747, as an industrialized, subscription-based phishing ecosystem that automated MFA bypass at scale. Microsoft’s Digital Crimes Unit disrupted the operation, seizing 330 domains with Europol and partners, and urges organizations to prioritize agent inventory, agentic accountability, and lifecycle-integrated intelligence and defenses.
read more →

EvilTokens Abuses Microsoft Device-Code Flow for Takeovers

⚠️ Sekoia researchers uncovered a phishing-as-a-service toolkit named EvilTokens that abuses Microsoft's device code authentication flow to capture valid access tokens by tricking victims into entering device codes on official Microsoft login pages. The kit bundles phishing lures, AI-driven automation, inbox harvesting and post-compromise modules to weaponize access. Operators distribute the service through Telegram bots and channels, and Sekoia observed activity since at least mid-February targeting countries including the US, Australia, Canada, France, India, Switzerland and the UAE.
read more →

Microsoft Links Classic Outlook Bug to Email Delivery Issues

📧 Microsoft is investigating a known issue that prevents some Classic Outlook users from sending messages via Outlook.com, causing non-delivery reports that indicate permission errors (0x80070005-0x0004dc-0x000524). The problem is more likely when the Outlook.com account is an Outlook profile linked to another Exchange account or when an Exchange Online mail contact shares the same SMTP address. Microsoft published temporary workarounds — remove the M365 account Address Book, hide the Outlook.com contact in the Global Address List, create a fresh Classic profile with only the affected account, or use the New Outlook client or webmail until a permanent fix is deployed.
read more →

EvilTokens kit powers Microsoft device-code phishing

⚠️ EvilTokens is a commercially sold phishing kit that abuses the device code authorization flow to hijack Microsoft accounts and enable advanced BEC operations. Distributed via Telegram, campaigns deliver document lures with QR codes or links to phishing templates impersonating trusted services and workflows. Victims are prompted to authenticate on the real Microsoft device login, producing short-lived access tokens and refresh tokens that give attackers immediate and persistent access. Sekoia reported global campaigns and published IoCs and YARA rules; the author says support for Gmail and Okta is planned.
read more →

Emergency Windows 11 KB5086672 Fixes Install Failures

🛠️ Microsoft released an out-of-band update, KB5086672, to replace the broken March preview KB5079391 and address installation failures that produced Error 0x80073712 on Windows 11 24H2 and 25H2 systems. The cumulative OOB update supersedes prior March protections and improvements and may be offered automatically to devices with "Get the latest updates" enabled. If that setting is off, install via Settings > Windows Update > Download & install.
read more →

WhatsApp-delivered VBS Campaign Installs MSI Backdoors

🛡️ Microsoft Defender Experts (DEX) observed a late-February 2026 campaign leveraging WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Executing the VBS creates hidden folders under C:\ProgramData, drops renamed legitimate Windows utilities, and uses them to download additional payloads from cloud services such as AWS, Tencent Cloud, and Backblaze B2. Attackers escalate privileges, tamper with UAC and registry settings, and install unsigned MSI packages to establish persistent remote access. Microsoft recommends hardening script hosts, monitoring cloud traffic and registry changes, and enabling Defender protections.
read more →

Microsoft fixes Outlook Classic crashes from Teams add-in

🛠️ Microsoft has resolved a bug that caused the classic Outlook client to crash when the Microsoft Teams Meeting Add-in was enabled. First reported on March 12 and tracked under incident EX1254044, the issue occurred when older Outlook builds used the Teams Meeting Add‑in build 1.26.02603, for example Current Channel Outlook <= Version 2402 (Build 17328.20142). A fix is rolling out with Teams version 26058.712.4527.9297; Microsoft recommends updating Outlook to the latest build or performing an Online Repair for click‑to‑run installs. As a temporary workaround, users who must remain on an older Office build can disable the Teams Meeting Add‑in via Outlook Safe Mode (Ctrl on launch) and the COM Add‑ins dialog.
read more →

Amazon RDS for SQL Server Developer Edition in GovCloud

🆕 Amazon RDS for SQL Server now offers Microsoft SQL Server Developer Edition in the AWS GovCloud (US) Regions. Developer Edition is a free, full-featured, non-production license that mirrors Enterprise capabilities, helping teams reduce licensing costs for development, testing, and demonstrations. Amazon RDS-managed features — automated backups, automated software updates, monitoring, and encryption — are supported for SQL Server 2019 and SQL Server 2022 instances.
read more →

Navigating Digital Sovereignty: Microsoft's Practical Path

🔒 Microsoft frames digital sovereignty as a practical, consultative discipline that extends beyond privacy to encompass continuity, resilience, and responsible AI adoption. The post outlines a Sovereign Cloud continuum—including the EU Data Boundary, hybrid and private cloud options, and expanded disconnected operations—to provide organizations with choice, visibility, and control. It emphasizes transparency, risk-based engagement, and long-term accountability as core means to build durable trust while enabling innovation.
read more →

Microsoft Named a Leader in Gartner 2026 IPaaS MQ Report

🚀 Microsoft was named a Leader in the 2026 Gartner Magic Quadrant for Integration Platform as a Service, its eighth consecutive year of recognition. The company positions Azure Integration Services as a unified platform to connect applications, data, APIs, and events while operationalizing AI across the enterprise. With Azure Logic Apps and Azure API Management, Microsoft highlights support for agentic workflows, embedded governance, and AI Gateway capabilities to enforce policies, manage usage, and ensure compliance as organizations scale AI-driven operations.
read more →

Microsoft Pauses Windows KB5079391 After Install Errors

⚠️ Microsoft has paused the rollout of a Windows 11 preview update, KB5079391, after reports that installations fail with error 0x80073712. The optional cumulative update targeted Windows 11 24H2 and 25H2 and bundled 29 changes, including Smart App Control, display improvements, improved Windows Hello fingerprint reliability, and Windows RE stability for x64 apps on ARM64 devices. To prevent further impact, Microsoft has temporarily limited the update's availability through Windows Update while it investigates and said the issue will most likely be resolved before the April 14 Patch Tuesday, though no firm timeline was provided.
read more →

Windows 11 KB5079391 Preview Adds Smart App Control

🛡️ Microsoft released the KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, delivering 29 non-security changes and optional fixes. The update lets administrators and users toggle Smart App Control on or off without reinstalling the OS via Settings > Windows Security > App & Browser Control. It also introduces display reliability enhancements, including support for monitors reporting refresh rates above 1000 Hz, native USB4 monitor connections, and improved HDR behavior. Installers can apply the preview via Windows Update or the Microsoft Update Catalog; installation is optional unless automatic preview updates are enabled.
read more →