< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 23 of 48

Iran-linked Group Claims Massive Wiper Attack on Stryker

🚨 Pro-Iranian group Handala claimed it wiped over 200,000 devices and exfiltrated 50TB of data from medical device maker Stryker, asserting offices in 79 countries were forced to close. Stryker confirmed a cyber incident causing global disruption to its Microsoft environment but said there is no indication of ransomware and that it believes the incident is contained. Experts warned the attack appears to have leveraged enterprise management tools such as Microsoft Intune, suggesting a credential compromise and tactics consistent with Iranian state-linked activity.
read more →

Dozens of Vendors Patch Critical and High-Risk Flaws

🔒 SAP, Microsoft, Adobe and many other vendors released patches this month for multiple critical and high‑risk vulnerabilities, including remote code execution and authentication bypasses. SAP addressed two critical flaws — CVE-2019-17571 (Log4j 1.2.17, CVSS 9.8) and CVE-2026-27685 (insecure deserialization, CVSS 9.1) — while Microsoft and Adobe shipped fixes for dozens more. Hewlett Packard Enterprise patched an Aruba AOS‑CX authentication bypass (CVE-2026-23813, CVSS 9.8). Organizations should prioritize fixes for RCE, insecure deserialization, and authentication-bypass issues on Internet-facing and management interfaces.
read more →

Microsoft Patches Two Publicly Disclosed Zero-Day Flaws

🔒 Microsoft released its March Patch Tuesday updates addressing 79 vulnerabilities, including two publicly disclosed zero-day flaws. The zero-days are CVE-2026-21262, an SQL Server elevation-of-privilege issue (CVSS 8.8), and CVE-2026-26127, a .NET denial-of-service vulnerability. Security researchers warn that while only three flaws were rated critical, the bulk of fixes are elevation-of-privilege bugs in core Windows components and should be prioritised to avoid escalation chains and operational disruption.
read more →

Microsoft March Patch Tuesday: 84 Flaws, 2 Zero-Days

🔒Microsoft released its March Patch Tuesday updates addressing 84 security vulnerabilities, including two publicly disclosed zero-days. Of the fixes, eight are rated Critical and 76 Important, spanning privilege escalation, remote code execution, information disclosure and other classes. The highest-scoring issue is CVE-2026-21536 (CVSS 9.8) in the Microsoft Devices Pricing Program, which Microsoft says is fully mitigated. Administrators should review MSRC advisories and apply updates based on risk and exposure.
read more →

Microsoft Patch Tuesday — March 2026 Security Fixes

🔒 Microsoft released fixes for at least 77 vulnerabilities across Windows and related products in its March 2026 Patch Tuesday. Two issues were previously disclosed publicly, including a SQL Server privilege elevation (CVE-2026-21262) that can allow network-based escalation to sysadmin. Several critical remote code execution bugs in Microsoft Office and other components, plus a notable AI-discovered 9.8-rated RCE (CVE-2026-21536), merit prioritized attention. Administrators should review privilege escalation and RCE patches first and monitor for any post-update issues.
read more →

March Patch Tuesday: High-Severity Microsoft Office Flaws

🛡️ Microsoft’s March Patch Tuesday addresses 78 vulnerabilities, led by three high-severity flaws in Microsoft Office, including an Excel information-disclosure bug (CVE-2026-26144) and two remote-code-execution issues (CVE-2026-26113, CVE-2026-26110). While Microsoft reports no known zero-day exploitation, experts urge expedited patching, restricting outbound Office traffic, and limiting AI automation such as Copilot Agent to mitigate potential silent exfiltration and preview-pane attack vectors.
read more →

Microsoft March 2026 Patch Tuesday: 79 Vulnerabilities

🔒 Microsoft issued its March 2026 Patch Tuesday addressing 79 vulnerabilities, three of which were marked critical though assessed as less likely to be exploited. The critical issues include Office remote code execution bugs (CVE-2026-26110, CVE-2026-26113) and an Excel information-disclosure flaw (CVE-2026-26144). Important fixes affect SharePoint, SQL Server and multiple Windows components. Cisco Talos published Snort and firewall rules to detect exploitation attempts and urges customers to apply patches and rule updates promptly.
read more →

Microsoft Releases Windows 10 KB5078885 Security Update

🔒 Microsoft has released the Windows 10 KB5078885 extended security update for Enterprise LTSC and ESU devices. Install via Settings → Windows Update to move systems to build 19045.7058 (or 19044.7058 for LTSC 2021); the update consolidates March 2026 Patch Tuesday fixes that address 79 vulnerabilities, including two actively exploited zero-days. It also fixes a shutdown/hibernation bug and advances a controlled rollout of new Secure Boot certificates to maintain boot-time validation.
read more →

Microsoft March 2026 Patch Tuesday: 79 Flaws, 2 Zero-Days

🔒 Microsoft's March 2026 Patch Tuesday addresses 79 vulnerabilities, including two publicly disclosed zero-days and three Critical flaws. Notable fixes include two Office remote code execution bugs exploitable via the preview pane and an Excel information-disclosure issue that could enable data exfiltration via Copilot. Administrators should prioritize Office, Windows and Azure updates immediately.
read more →

Windows 11 KB5079473 and KB5078883 Updates Released

🛡️ Microsoft released cumulative updates KB5079473 and KB5078883 for Windows 11 (25H2/24H2 and 23H2) delivering the March 2026 Patch Tuesday security fixes, bug repairs, and new features. These mandatory updates can be installed via Start > Settings > Windows Update or downloaded from the Microsoft Update Catalog, and will increment build numbers for each channel. Highlights include expanded Secure Boot certificate targeting, a native Sysmon option, Emoji 16.0 additions, Quick Machine Recovery, and multiple reliability and UX improvements.
read more →

Microsoft Entra Adds Phishing-Resistant Passkeys on Windows

🔐 Microsoft is introducing passkey support in Microsoft Entra for Windows, enabling phishing-resistant, passwordless sign-ins via Windows Hello. The opt-in feature enters public preview worldwide from mid‑March through late April 2026, with government clouds (GCC, GCC High, DoD) following mid‑April through mid‑May. Passkeys are device-bound, stored in the Windows Hello container, and never transmitted over the network, preventing credential theft and MFA bypass. IT administrators must enable the Passkeys (FIDO2) authentication method, create a passkey profile including the required Windows Hello AAGUIDs, and assign the profile to appropriate groups to enroll devices.
read more →

Microsoft to Enable Hotpatch Security Updates by Default

🔔 Starting with the May 2026 Windows security update, Microsoft will enable hotpatch security updates by default for all eligible devices managed via Microsoft Intune and the Microsoft Graph API. The updates will be delivered through Windows Autopatch and are intended to halve the time to reach 90% patch compliance by applying fixes without requiring immediate restarts. Organizations can opt out at the tenant level through Intune controls that go live April 1, 2026, and administrators should use the Hotpatch quality updates report to confirm device readiness.
read more →

March 2026 Patch Tuesday: 82 CVEs, 8 Critical Vulns

🔒 Microsoft’s March 2026 Patch Tuesday addresses 82 vulnerabilities, including eight Critical issues and two publicly disclosed flaws affecting Windows, Azure and Office. Notable high-severity items include a CVSS 9.8 RCE in the Microsoft Devices Pricing Program and several elevation-of-privilege and RCE flaws in Office, Excel and Azure Confidential Containers; some cloud-hosted issues were remediated server-side with no customer action required. CrowdStrike recommends prioritizing available fixes, applying mitigations where patches are absent, and using the Falcon Patch Tuesday dashboard to triage and track remediation.
read more →

Unpacking Agentic AI: The Shift Podcast Launch and Insights

🎧 Microsoft introduces The Shift, an evolution of its earlier podcast to explore agentic AI across engineering, product, and strategy perspectives. Over eight weekly episodes this spring, hosts and guests from teams including Microsoft Azure, Microsoft Fabric, and Microsoft Foundry tackle practical questions about how agents interact with data, databases, and cloud foundations. Episodes emphasize that agents succeed only when data strategy, cloud reliability, and application orchestration work together, highlighting operational concerns like observability, governance, security, and optimization.
read more →

Microsoft Teams Will Tag Third-Party Bots in Lobbies

🛡️Microsoft will update Teams to clearly label external third-party bots that appear in meeting lobbies, and organizers will be required to explicitly admit them. The change is slated for May 2026 and will reach Windows, macOS, Android, and iOS for worldwide standard multi-tenant and GCC clouds. By distinguishing bots from human attendees, the feature aims to prevent malicious or unwanted automated participants from being inadvertently accepted into meetings and complements recent Teams security enhancements such as call-reporting, fraud-protection warnings, and Defender-based admin controls.
read more →

Microsoft still fixing Windows Explorer white flashes

🔧Microsoft has confirmed it is still working to fully resolve a bug that causes bright white flashes when opening File Explorer on some Windows 11 systems. The company has rolled fixes to Windows Insiders in the Beta and Dev channels via preview builds Build 26220.7961 (KB5079382) and Build 26300.7965 (KB5079385). Those updates remove white flashes when launching new Explorer windows or tabs and when resizing elements, and also add voice typing and improved file unblocking reliability. Microsoft originally linked the issue to the optional KB5070311 update in December.
read more →

Secure Agentic AI with Microsoft Agent 365 and E7 Suite

🛡️ Microsoft today unveiled Agent 365 and Microsoft 365 E7: The Frontier Suite, generally available May 1, 2026, to help organizations observe, secure, and govern agentic AI at scale. Agent 365 provides a unified control plane with an agent registry, behavior and performance observability, and integrated risk signals across Microsoft Defender, Entra, and Purview. The offering extends identity and access controls with Agent ID, conditional access, and identity governance, while Purview features such as Inline DLP for Copilot Studio prompts, information protection, and data lifecycle management help prevent sensitive data exposure. Pricing starts at $15 per user per month for Agent 365 and $99 per user per month for Microsoft 365 E7.
read more →

Tycoon 2FA phishing kit dismantled after global takedown

🔒In a coordinated takedown, law enforcement and industry partners dismantled Tycoon 2FA, a commercial phishing-as-a-service platform that automated MFA bypasses via a real-time proxy. The kit, sold for about US $120/month through private Telegram channels, forwarded credentials and one-time codes to legitimate sites to capture authenticated sessions. It was linked to tens of millions of phishing emails and widespread attacks on healthcare and education before seizures and blocks by Microsoft, multi-country law enforcement, and Cloudflare largely disrupted the operation. Users are reminded that not all MFA is equal: hardware security keys or passkeys provide stronger protection against proxying than SMS-based codes.
read more →

Forrester TEI: Microsoft Foundry's Enterprise AI ROI

🔎 The Forrester Total Economic Impact study modeled a composite $10B enterprise using Microsoft Foundry and estimated a 327% ROI over three years, with developer productivity identified as the largest contributor at $15.7M. Foundry reduced undifferentiated engineering work and improved technical team productivity up to 35%, with some teams seeing payback in as few as six months. Its unified platform, reusable knowledge bases, built-in evaluations, and agent controls also enabled organizations to decommission legacy tools and avoid infrastructure costs.
read more →

Microsoft 365 Backup Adds File-Level Restore for Admins

🗂️ Microsoft will add granular file- and folder-level restore to Microsoft 365 Backup, allowing administrators to browse, search and recover individual files from SharePoint and OneDrive restore points rather than restoring entire sites or drives. The capability is limited to tenants with the backup service enabled and requires the SharePoint Backup Administrator role; end users will not see restore operations. Public preview began in early March 2026 and Microsoft expects general availability between late April and early May 2026. Customers are advised to review coverage, train backup administrators, and update recovery runbooks to incorporate file- and folder-level restores.
read more →