< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 22 of 48

CISA Urges Hardening of Endpoint Management Systems

🔒 CISA warns of malicious activity targeting endpoint management systems following the March 11, 2026 attack against Stryker Corporation that affected its Microsoft environment. The agency urges organizations to harden endpoint management configurations and adopt Microsoft’s newly released best practices for securing Microsoft Intune, while applying those principles to other endpoint management tools. Key recommended controls include RBAC-based least-privilege administrative roles, phishing-resistant MFA and privileged access hygiene using Microsoft Entra ID, and configuring Multi Admin Approval policies for high-impact actions such as device wipes, application and script changes, and RBAC modifications.
read more →

Microsoft halts automatic install of 365 Copilot app

🔔 Microsoft has halted the planned automatic installation of the Microsoft 365 Copilot app on Windows devices outside the EEA. The rollout, announced earlier and scheduled for December, is temporarily disabled; existing installs are unchanged and administrators can still deploy the app manually. Microsoft offered no reason in its Microsoft 365 message center update and asked admins to await further information. EEA customers remain excluded from the change.
read more →

Windows 11 hotpatch fixes Bluetooth device visibility issue

🔧 Microsoft released an out-of-band hotpatch (KB5084897) to address a Bluetooth device visibility problem impacting hotpatch-enabled Windows 11 Enterprise systems. Connected Bluetooth peripherals may not appear in Settings or Quick Settings, and users might be unable to add new devices because available devices are not listed. The update targets Windows 11 25H2 and 24H2, installs automatically on eligible Enterprise clients, and requires no restart.
read more →

Microsoft: Teams Meeting Add-in Breaks Outlook Classic

⚠️ Microsoft warns that enabling the Microsoft Teams Meeting Add-in can render the classic Outlook desktop client unusable for affected users, according to an admin center notice (EX1254044). The company says the problem is tied to a previous Outlook build and is working with customers to ensure the latest version is deployed. As a temporary fix, impacted users should update Outlook or run an Online Repair for click-to-run installs, which reinstalls Office apps.
read more →

Microsoft, NVIDIA Expand Azure AI Infrastructure and Foundry

🚀 Microsoft and NVIDIA announced deeper integration at NVIDIA GTC, extending Microsoft Foundry to support NVIDIA Nemotron models and to simplify building production agents. New Azure AI infrastructure optimized for inference and reasoning will bring Vera Rubin NVL72 into liquid‑cooled datacenters and add initial support on Azure Local. Foundry Agent Service, Control Plane observability and a Voice Live API preview aim to accelerate prototype‑to‑production paths, while Fabric–Omniverse links and a public Physical AI Toolchain support simulation‑to‑operations workflows.
read more →

Stryker Attack Wipes Tens of Thousands of Devices Globally

🔒 Stryker reported a targeted attack that remotely wiped nearly 80,000 corporate devices by abusing Microsoft admin privileges and issuing remote wipe commands through Intune. The company says the incident was confined to its internal Microsoft environment, did not involve deployed malware, and investigators found no evidence of data exfiltration. Operational impacts include offline electronic ordering systems and manual order processing while recovery continues.
read more →

Microsoft Purview innovations for Fabric governance

🔒 Microsoft announced new Purview innovations for Fabric to help organizations discover sensitive data risks, prevent oversharing, and improve governance and data quality across their data estate. Updates include general availability of DLP policies for Fabric Warehouses and KQL/SQL DBs, Insider Risk Management for lakehouses, and preview capabilities for Copilots and Agents. The Unified Catalog also gains publication workflows and data quality checks for ungoverned assets to better prepare trusted data for AI.
read more →

From Legacy to Leadership: PostgreSQL on Azure for Agility

🚀 Microsoft outlines how moving from legacy on-prem Oracle to Azure Database for PostgreSQL and the new Azure HorizonDB can reduce costs, boost performance, and improve agility. The post highlights an Apollo Hospitals migration that cut operational costs by 60%, improved uptime to 99.95%, and delivered a 3x performance gain. It also describes an AI-assisted Oracle-to-PostgreSQL migration tool integrated into VS Code that automates schema and application conversion, testing, and validation to reduce risk and accelerate adoption.
read more →

Microsoft Exchange Online outage blocks mailbox access

📧Microsoft is investigating an ongoing Exchange Online outage that is preventing customers from accessing mailboxes and calendars. The company acknowledged the incident at 06:42 AM UTC and reported problems across Outlook on the web, Outlook desktop, Exchange ActiveSync, and other Exchange Online connection protocols. Microsoft said telemetry shows recovery for some users while engineers apply configuration changes and continue to monitor service health.
read more →

Vishing Leads to Compromise via Microsoft Teams Support

🔒 In this Cyberattack Series report, Microsoft Incident Response (DART) details an identity-first, human-operated intrusion that began with persistent Microsoft Teams voice phishing (vishing). After two failed attempts, the attacker persuaded a third employee to grant remote access via Quick Assist, then directed the user to a spoofed web form to capture corporate credentials and download multiple payloads. An early, disguised MSI sideloaded a malicious DLL to establish outbound command-and-control. DART contained the activity, removed artifacts, and recommends tightening external collaboration and disabling unnecessary remote-access utilities.
read more →

Microsoft Removes Samsung App After C: Drive Access Issues

⚠️ Microsoft removed the Samsung Galaxy Connect app from the Microsoft Store after a joint investigation concluded the app (used for screen mirroring, file sharing and data transfer) was triggering "C:\ is not accessible – Access denied" errors on certain Windows 11 Samsung Galaxy Book 4 and desktop models. Affected users reported blocked applications, failure to access files, and privilege elevation problems that impeded diagnostics. Samsung republished a stable previous version to stop further occurrences, but recovery options for impacted devices remain limited. Microsoft and Samsung have not published a workaround yet; users should contact Samsung for device-specific support.
read more →

Google and Partners Sign Global Accord to Combat Scams

🤝 Google announced it has signed the Industry Accord Against Online Scams & Fraud with major industry partners including Adobe, Amazon, LinkedIn, Meta, Microsoft and OpenAI. The agreement commits participants to unify capabilities, share threat intelligence and coordinate defenses against sophisticated, cross-border scam networks. Google said it will expand technical support and deploy AI-driven detection tools, building on $15 million in Google.org funding. In 2026 the company will share more through the Global Signal Exchange and publish guides on data sharing, private sector referrals to law enforcement, and public policy frameworks.
read more →

Microsoft issues Windows 11 hotpatch for RRAS RCE update

🔧 Microsoft released an out-of-band hotpatch (KB5084597) for Windows 11 to address remote code execution flaws in the Routing and Remote Access Service (RRAS) management tool. The update patches CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111 and aligns with fixes shipped in the March 2026 Patch Tuesday release. The hotpatch performs in-memory patching so eligible Enterprise devices enrolled in the hotpatch program via Windows Autopatch receive cumulative fixes without a restart. It applies to Windows 11 25H2, 24H2, and Enterprise LTSC 2024 systems used for remote server management.
read more →

Windows 11: Some Samsung PCs Lose Access to C Drive

⚠️Microsoft is investigating reports that some Samsung laptops running Windows 11 lose access to the C:\ drive after installing the February 2026 security updates. Affected users encounter the error 'C:\ is not accessible - Access denied' and cannot launch applications such as Outlook, Office apps, web browsers, and system utilities. Microsoft says it is working with Samsung and that the problem may be related to the Samsung Share application, but no official workaround has been provided.
read more →

Microsoft Probes Classic Outlook Sync and Connection Issues

📧 Microsoft is investigating several issues that are disrupting email synchronization and server connections in the classic Outlook desktop client. One bug causes 'Can't connect to the server' errors when creating groups if Exchange Web Services (EWS) is enabled because an AD Graph validation call fails; Microsoft plans updated group functionality using REST APIs and recommends using the new Outlook or OWA until a fix is released. Separate reports describe 0x800CCC0F and 0x80070057 errors for Gmail and Yahoo accounts after password changes — a temporary workaround is to delete the affected identity registry entries — and a cursor disappearance bug affecting Outlook and some Microsoft 365 apps is also under investigation.
read more →

Handala Hack Wiper Attacks Targeting Intune Admins

🔒 Unit 42 warns of elevated risk from destructive wiper operations attributed to the Iranian-linked Handala Hack actor, which has used phishing and compromised Microsoft Intune administrative access to delete servers and devices and disrupt operations. The actor, first seen in late 2023 and also tracked as Void Manticore, COBALT MYSTIQUE and Storm‑1084/0842, is assessed as a state-directed front for Iran’s MOIS. Mitigations focus on eliminating standing privileges (JIT, PIM), hardening Entra ID and Intune admin roles, enforcing conditional access and hardware MFA, reducing session lifetimes and ensuring immutable offline backups.
read more →

Stryker hit by widespread device wipes linked to Iran

🛡️ Stryker reported a large-scale disruption after thousands of employee devices were remotely wiped and many users were unable to log in, saying the issue appears contained to its internal Microsoft environment and that there is no indication of malware at this time. The pro-Iranian group Handala claimed responsibility and employees reported seeing its logo on affected machines. Analysts say the pattern is consistent with a compromise of Microsoft Intune and Entra-based admin controls, which would permit remote wiping without deploying traditional malware, and recommend tightened admin verification and credential protections.
read more →

Storm-2561 SEO poisoning distributes fake VPN clients

🔒 Microsoft Threat Intelligence attributes a mid‑January 2026 credential theft campaign to the cybercriminal group Storm‑2561, which used SEO poisoning to surface malicious ZIP files masquerading as legitimate enterprise VPN installers. The ZIPs contained an MSI that side‑loaded signed trojan DLLs (dwmapi.dll and inspector.dll) which harvested VPN credentials and exfiltrated configuration data to attacker infrastructure. The binaries were signed with a certificate issued to Taiyuan Lihua Near Information Technology Co., Ltd. (now revoked), and the installers mimicked a Pulse Secure client to trick users; GitHub hosts were used but have been removed.
read more →

Latest Microsoft Email Security Benchmark Findings

🛡️ Microsoft published updated email security benchmarks comparing Defender, secure email gateways (SEGs), and integrated cloud email security (ICES) solutions. The data shows Microsoft Defender removes an average of 70.8% of malicious email post-delivery, with ICES partners contributing the remaining 29.2% of post-delivery remediation. Layering matters: integrated ICES solutions improve marketing and bulk filtering by an average of 13.7%, while incremental gains for spam and malicious filtering were modest (around 0.29% and 0.24% respectively). The report also compares misses per 1,000 users, showing Defender had fewer high-severity misses than several evaluated SEG vendors.
read more →

Detecting and Responding to Prompt Abuse in AI Tools

🔍 This post, the second in Microsoft's AI Application Security series, moves from planning to practical detection and response for prompt abuse. It describes common attack types — direct prompt override, extractive abuse targeting sensitive inputs, and indirect prompt injection via hidden instructions such as URL fragments — and why these are hard to spot without telemetry. The article provides a stepwise detection and incident response playbook and maps mitigations to Microsoft tools so teams can log interactions, sanitize inputs, and contain incidents.
read more →