< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 21 of 48

Identity Security: The New Pressure Point in Cyberattacks

🔐 Microsoft argues that identity is the primary pressure point for modern cyberattacks as organizations manage proliferating human, non-human, and agentic identities across disparate systems. The post highlights that fragmentation—duplicative solutions and too many vendors—creates visibility gaps that enable lateral movement. It outlines a unified model built on Microsoft Entra, a real-time identity control plane including Conditional Access, and integrated threat protection, and describes AI-driven triage with Security Copilot to accelerate response and reduce analyst fatigue.
read more →

AI for Nuclear Energy: Building Intelligent Resilience

⚛️ Microsoft announces an AI for nuclear collaboration with NVIDIA to deliver an end-to-end, AI-powered foundation for nuclear project delivery. The initiative pairs Microsoft Azure, generative AI for permitting, and NVIDIA simulation and AI stacks to speed design, streamline licensing, and improve operations via Digital Twins. Early adopters — including Aalo Atomics, Southern Nuclear, and Idaho National Laboratory — report major time and cost reductions while preserving regulatory traceability and security.
read more →

Device Code Phishing Targets 340 Microsoft Orgs Globally

🔐 Huntress is tracking an active device code phishing campaign targeting Microsoft 365 identities at over 340 organizations across the US, Canada, Australia, New Zealand, and Germany. The attackers use Cloudflare Workers redirects and Railway.com-hosted infrastructure to harvest OAuth access and refresh tokens that remain valid after password resets. Sectors hit include construction, non-profits, real estate, manufacturing, finance, healthcare, legal and government.
read more →

Microsoft fixes Outlook sync bug affecting Gmail users

🔧 Microsoft has resolved a known issue that caused Classic Outlook to stop syncing Gmail and Yahoo accounts and to show 0x800CCC0F and 0x80070057 error codes. Affected accounts reportedly stopped syncing on February 26, 2026; Microsoft says the fix was applied in the Microsoft 365 service, but some users may still see issues until their OAuth token expires. As a temporary workaround, Microsoft recommends deleting the affected email address entries under the Identities key at Computer\HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities to force a sign-in prompt.
read more →

Microsoft Open Source and AKS at KubeCon Europe 2026

🚀 At KubeCon + CloudNativeCon Europe 2026, Microsoft outlined coordinated open-source and AKS enhancements designed to bring AI workloads to Kubernetes with enterprise-grade operational patterns. Upstream work includes DRA reaching GA, Workload Aware Scheduling for Kubernetes 1.36, DRANet Azure RDMA compatibility, and new projects such as AI Runway, HolmesGPT (CNCF Sandbox), and Dalec. AKS platform updates add identity-aware networking with Azure Kubernetes Application Network, meshless Istio routing, WireGuard and Cilium-based encryption, built-in GPU telemetry into managed Prometheus/Grafana, per-flow L3/L4 and L7 observability, a managed Cilium cluster mesh via Fleet Manager, Elastic SAN shared storage, AKS Desktop GA, and safer upgrades with blue-green agent pool upgrades and agent pool rollback.
read more →

Tycoon2FA Phishing Service Resumes After Disruption

🔁 Tycoon2FA, a phishing-as-a-service platform disrupted by Europol and Microsoft on March 4, has returned to pre-takedown activity levels within days. CrowdStrike observed a brief decline to about 25% of normal volumes on March 4–5, 2026, before activity rebounded and cloud compromise remediations returned to early-2026 levels. The service continues to use similar TTPs targeting Microsoft 365 and Gmail, exploiting redirection, URL shorteners, and compromised domains. CrowdStrike warns that without arrests or physical seizures, operators can quickly recover and replace impacted infrastructure.
read more →

Microsoft virtual account change disrupts Exchange Online

⚠️ Microsoft is addressing an intermittent Exchange Online outage that has blocked some users from accessing mailboxes via Outlook mobile and the new Outlook for Mac client since Thursday. The company traced the issue (incident EX1256020) to a newly introduced virtual account and is reverting that change across affected environments. Restarts failed to resolve the problem, and Microsoft is working on a permanent remediation and will provide a timeline when available.
read more →

Microsoft: IRS-themed Phishing Hits 29,000, RMM Abused

⚠️Microsoft reported large-scale IRS-themed phishing campaigns in February 2026 that targeted more than 29,000 users across 10,000 organizations, using tax refund, payroll and W‑2 lures to harvest credentials and deliver remote access tools. Attackers leveraged Phishing-as-a-Service kits (notably Energy365 and SneakyLog/Kratos) and abused legitimate RMM products such as ScreenConnect, Datto, and SimpleHelp to maintain persistent access. Microsoft advises enforcing 2FA, applying conditional access, and blocking malicious domains and payloads to reduce exposure.
read more →

Microsoft issues KB5085516 to fix account sign-in bug

🔧 Microsoft released an out-of-band update, KB5085516, to fix a sign-in failure that prevented Microsoft account authentication in multiple apps after the March cumulative update KB5079473. Affected apps included Microsoft Edge, Teams, OneDrive, Microsoft 365 Copilot and Office apps, which reported the device was not connected to the Internet. The optional fix is available for Windows 11 25H2 and 24H2 via Windows Update or the Microsoft Update Catalog, and Microsoft recommends installing the latest updates.
read more →

Water Utilities Boost Cybersecurity Through Cooperation

💧Water utilities facing aging operational systems and limited IT staff are improving cybersecurity by sharing information and coordinating responses. A two-year pilot led by the Cyber Readiness Institute and the Center on Cyber and Technology Innovation, sponsored by Microsoft, enrolled about 200 small and mid-sized utilities. The study found that combining cybersecurity training with hands-on technical assistance, stronger sector links and practical support is more effective than distributing guidance alone.
read more →

CTI-REALM: Benchmark for End-to-End Detection Rules

🔍 Microsoft introduces CTI-REALM, an open-source benchmark that evaluates AI agents on end-to-end detection engineering by turning real-world cyber threat intelligence into validated detections. The benchmark places agents in realistic, tool-rich environments where they must read CTI reports, explore telemetry, iterate on KQL queries, and produce Sigma rules and KQL-based logic scored against ground truth across Linux, AKS, and Azure. CTI-REALM's checkpoint-based scoring surfaces whether failures arise from CTI comprehension, technique mapping, data-source selection, or query construction, helping teams decide where human oversight and guardrails are required.
read more →

Securing Agentic AI: End-to-End Enterprise Protections

🔒 Microsoft presents an end-to-end strategy to secure agentic AI with the new Agent 365 control plane and updates across Microsoft Defender, Entra, Purview, and Sentinel. Announced for RSAC 2026, these measures focus on visibility, continuous identity protection, data loss prevention for Copilot prompts, and prompt-injection defenses to help organizations observe, govern, and defend agent ecosystems at scale.
read more →

KB5079473: March Windows 11 Update Breaks Sign-Ins

🛠️ Microsoft says the March Windows 11 cumulative update KB5079473 causes Microsoft account sign-in failures across multiple apps, including Teams, OneDrive, Edge, Excel, Word and Microsoft 365 Copilot. Affected apps display an erroneous message indicating the device is offline even when connected. Microsoft recommends restarting affected devices while they remain online as a temporary workaround while it works on a fix. Business sign-ins using Entra ID are not impacted.
read more →

CISA Warns to Harden Endpoint Management After Intune Attack

🔒 CISA is urging IT and security leaders to harden endpoint management configurations after pro‑Iranian group Handala reportedly abused Microsoft Intune in a March 11 attack on Stryker that disrupted operations and enabled remote wipes. The guidance emphasizes least‑privilege administrative roles, phishing‑resistant MFA, privileged access hygiene, and multi‑admin approval for destructive actions. Although focused on Intune, CISA says these defensive principles apply to any UEM. Organizations should audit admin access, require multi‑party approvals, and continuously monitor privileged activity.
read more →

Microsoft Announces Zero Trust for AI: New Tools and Guidance

🔒 Microsoft announced Zero Trust for AI, extending proven Zero Trust principles across the AI lifecycle and shipping new tools and guidance to help security teams deploy AI with confidence. The update adds an AI pillar to the Zero Trust Workshop, expands the Zero Trust Assessment to include Data and Networking, and introduces a Zero Trust for AI reference architecture. Microsoft also published practical patterns for threat modeling and AI observability to help teams verify agents, apply least privilege, and assume breach.
read more →

Critical Microsoft SharePoint Flaw Now Exploited in Attacks

🔴 The Cybersecurity and Infrastructure Security Agency (CISA) warned that a critical deserialization vulnerability in Microsoft SharePoint, tracked as CVE-2026-20963, is being exploited in the wild. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition and can allow unauthenticated remote code execution on unpatched servers. Microsoft patched the issue during January Patch Tuesday but has not labeled it as exploited; CISA added the vulnerability to its actively exploited catalog and ordered federal agencies to remediate by March 21.
read more →

CISA Alerts: Zimbra, SharePoint Flaws Actively Exploited

⚠ CISA has urged federal agencies to apply patches for two actively exploited vulnerabilities affecting Synacor Zimbra Collaboration Suite and Microsoft Office SharePoint. Zimbra's Classic UI suffered a stored XSS (CVE-2025-66376) patched in versions 10.0.18 and 10.1.13 in November 2025, while SharePoint had a deserialization RCE (CVE-2026-20963) fixed in January 2026. CISA set FCEB patching deadlines and reported no public attribution or scale; separately, Amazon detailed exploitation of a Cisco firewall-management zero-day (CVE-2026-20131) by the Interlock ransomware group.
read more →

Advancing Agentic AI Across a Unified Microsoft Data Estate

🚀 At SQLCon 2026 in Atlanta, Microsoft detailed enhancements that position its database portfolio as a foundation for agentic AI and unified analytics across edge, PaaS, and SaaS. Key announcements include Azure SQL innovations such as GitHub Copilot in SSMS, a one‑year Savings Plan for databases, and Hyperscale advances (vector index performance, SQL MCP Server, and larger vCore options). The new Database Hub in Microsoft Fabric (early access) and enterprise security features for SQL in Fabric aim to simplify migration, governance, and AI‑driven app development.
read more →

FabCon & SQLCon 2026: Unifying Databases and Fabric

🧩 Microsoft outlined a strategy at FabCon and SQLCon 2026 to converge its database portfolio and Microsoft Fabric into a single, unified data platform. Key highlights include the new Database Hub (early access) for unified estate management across Azure SQL, Cosmos DB, PostgreSQL, MySQL, SQL Server via Arc, and Fabric Databases. The company also showcased enhancements to OneLake, Runtime 2.0, Fabric IQ, agent experiences, migration assistants, and a database savings plan that can reduce costs up to 35% for eligible scenarios.
read more →

CISA Adds CVE-2026-20963 to Known Exploited Vulnerabilities

⚠️ CISA has added CVE-2026-20963 — a Microsoft SharePoint deserialization of untrusted data vulnerability — to its Known Exploited Vulnerabilities (KEV) Catalog after observing active exploitation. This class of flaw is a frequent attack vector that can allow malicious actors to execute code or manipulate data when untrusted input is deserialized. CISA reminds Federal Civilian Executive Branch agencies that BOD 22-01 requires remediation by the assigned due dates and strongly urges all organizations to prioritize timely fixes.
read more →