< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 24 of 48

GPT-5.4 in Microsoft Foundry: Production Reliability

🔧 Microsoft will make OpenAI's GPT-5.4 available soon through Microsoft Foundry, positioning the model for production-grade, agent-driven automation. GPT-5.4 emphasizes sustained multi-turn reasoning, improved instruction alignment, lower latency, and integrated computer-use capabilities for tool orchestration, file access, guarded code execution, and agent handoffs. A premium GPT-5.4 Pro targets deeper analytical workflows, while Foundry supplies policy, monitoring, versioning, and audit controls for enterprise deployment.
read more →

Malicious AI Assistant Extensions Harvest LLM Data

🔒 Microsoft Defender investigated malicious Chromium browser extensions that impersonated legitimate AI assistant tools to collect LLM chat histories and browsing telemetry. Distributed via the Chrome Web Store and compatible with both Google Chrome and Microsoft Edge, the extensions captured full URLs and chat snippets from platforms such as ChatGPT and DeepSeek, reaching roughly 900,000 installs and activity in over 20,000 enterprise tenants. Microsoft provides detections, hunting queries, and mitigation guidance to contain exposure and remediate affected devices.
read more →

Microsoft-led Takedown Disrupts Tycoon2FA Phishing Network

🔒 Microsoft led a court-authorized disruption of Tycoon2FA, a prominent phishing-as-a-service operation, seizing 330 active domains and coordinating infrastructure seizures with Europol and partner law enforcement. Private-sector partners including Cloudflare, Coinbase, Intel471, Proofpoint, the Shadowserver Foundation, SpyCloud and Trend Micro assisted in removing control panels and fraudulent login pages. Microsoft estimates Tycoon2FA accounted for roughly 62% of phishing attempts it blocked by mid-2025 and linked to about 96,000 victims since 2023.
read more →

Windows 10 KB5075039 Fixes Recovery Environment Issue

🔧 Microsoft released KB5075039 to repair a Windows 10 Recovery Environment (WinRE) startup failure caused by the October update KB5068164. The patch restores WinRE access for affected systems. Installation requires the WinRE partition to be at least 256 MB; administrators should back up drives before resizing partitions and follow Microsoft's manual resizing instructions.
read more →

Europol Disrupts Tycoon2FA Phishing-as-a-Service campaigns

🔒 Europol coordinated an international law enforcement operation that disrupted Tycoon2FA, a prolific phishing-as-a-service platform that intercepted credentials and session cookies via reverse proxies to bypass MFA and hijack authenticated sessions. Authorities seized 330 domains and removed control panels and phishing pages across multiple countries, with technical disruption led by Microsoft and support from private partners including Trend Micro and Cloudflare. The action aims to curb tens of millions of monthly phishing messages and protect nearly 100,000 targeted organizations while urging defenders to revoke active sessions and monitor for unauthorized access.
read more →

Global Takedown Disrupts Tycoon2FA Phishing Service

🛡️ Microsoft and Europol, supported by industry partners, seized infrastructure linked to the phishing-as-a-service operator Tycoon2FA, removing over 300 domains used in large-scale MFA-bypass campaigns. The PhaaS offering used adversary-in-the-middle techniques to intercept live authentication sessions and capture credentials, one‑time passcodes and session cookies in real time. Investigators say Tycoon2FA had roughly 2,000 users and leveraged more than 24,000 domains since launching in August 2023. Security firms recommend adopting phishing‑resistant authentication, strict conditional access and advanced email protections.
read more →

Hackers Abuse OAuth Error Redirects to Deliver Malware

🔐 Microsoft warns that attackers are abusing legitimate OAuth error redirection to bypass email and browser phishing protections and deliver malware. Campaigns target government and public-sector organizations with lures such as e-signature requests, meeting invites, and financial notices that contain OAuth redirect URLs. Attackers register malicious OAuth apps and invoke silent-auth parameters or invalid scopes to trigger error redirects to attacker-controlled pages. Those pages can host credential-phishing frameworks or automatically deliver ZIP packages that launch PowerShell loaders and DLL side‑loading routines, enabling final payload execution.
read more →

Microsoft Warns OAuth Redirect Abuse Targets Government Orgs

🔒 Microsoft warned on Mar 3, 2026 of phishing campaigns that leverage OAuth redirect URLs to bypass email and browser defenses and deliver malware to government and public-sector targets without directly stealing tokens. Attackers register malicious applications and manipulate identity providers like Entra ID and Google Workspace to craft redirect links sent in emails or embedded in PDFs. The delivery chain uses ZIP -> LNK-triggered PowerShell -> MSI -> DLL sideloading to execute in-memory payloads and contact external C2; some campaigns also used AitM kits such as EvilProxy. Microsoft removed identified malicious apps and recommends limiting consent, auditing app permissions, and removing unused or overprivileged applications.
read more →

OAuth Redirect Abuse Enables Phishing and Malware Delivery

🔒Microsoft Defender researchers observed phishing campaigns that abused OAuth redirection mechanics to route victims from trusted identity domains to attacker-controlled hosts. Attackers used silent authorization requests (for example prompt=none and intentionally invalid scopes) and embedded target addresses in the state parameter to trigger error redirects that landed users on malicious pages or download hosts without yielding tokens. Microsoft flagged correlated activity across email, identity, and endpoints; Microsoft Entra disabled the identified applications, though related activity persists and requires continued monitoring.
read more →

Florida woman jailed for large Microsoft license fraud

🔒 A Florida woman was sentenced to 22 months in prison and fined $50,000 for operating a years‑long scheme that trafficked thousands of stolen Microsoft Certificate of Authenticity (COA) labels. Heidi Richards, who ran Trinity Software Distribution, purchased tens of thousands of genuine COAs, had employees extract and transcribe product keys, and sold those keys in bulk to customers worldwide. Prosecutors reported she wired $5,148,181.50 to the supplier between July 2018 and January 2023.
read more →

Microsoft tests Windows 11 batch-file security mode

🔒 Microsoft is rolling out Windows 11 Insider Preview builds that introduce a secure processing mode for batch files and CMD scripts. Administrators can enable the feature via the LockBatchFilesInUse registry value under HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor or via the LockBatchFilesWhenInUse manifest control. When enabled, batch files cannot be modified while executing and signature validation runs once rather than per statement, improving both security and performance for scripted enterprise workflows.
read more →

Adapting Threat Modeling for AI Applications at Scale

🛡️ The Microsoft Security Blog explains why threat modeling must be retooled for AI systems, noting that probabilistic behavior and complex input spaces require reasoning about ranges of likely outcomes rather than single execution paths. It identifies three core drivers — nondeterminism, instruction‑following bias, and system expansion through tools and memory — which widen attack surfaces and surface human‑centered risks like erosion of trust. The post advises starting from assets, mapping untrusted inputs, setting clear 'never do' boundaries, and embedding architectural mitigations, observability, and response plans to limit blast radius and sustain trust.
read more →

Microsoft expands Windows restore to more enterprise devices

🔁Microsoft now enables enterprise users to restore personal settings and Microsoft Store apps from a previous Windows 11 device using the first sign-in restore experience in Windows Backup for Organizations. The update extends support beyond Microsoft Entra-joined machines to hybrid-managed environments, multi-user devices, and Windows 365 Cloud PCs, presenting a one-time restore prompt at first login. Administrators can control and deploy the feature through existing policies via Microsoft Intune or Group Policy, with general availability for devices that installed Windows updates released Feb 24, 2026 or later.
read more →

Microsoft expands Copilot data controls to all storage

🔒 Microsoft is extending Purview data loss prevention controls so the Microsoft 365 Copilot assistant cannot read or process sensitive Word, Excel, and PowerPoint files regardless of where they are stored. The change leverages the Office Augmentation Loop (AugLoop) component so Office clients can supply sensitivity labels for local files as well as for SharePoint and OneDrive. Microsoft will roll out the update between late March and late April 2026 and says it will be automatically enabled for tenants with DLP policies configured to block Copilot. The move follows a January bug that briefly allowed Copilot Chat to access and summarize protected emails.
read more →

Microsoft: Classic Outlook bug hides mouse pointer

🖱️ Microsoft is investigating a known issue that causes the mouse pointer to disappear for some users in the classic Outlook desktop client, making parts of the app difficult to use. The company acknowledged the bug nearly two months after initial reports and said the pointer — and in some cases the text cursor — can vanish as it moves across the interface while hover effects still occur. Microsoft asked affected organizations to open a support case with the Outlook Support Team and submit diagnostic logs, and offered temporary workarounds such as clicking a message, switching to PowerPoint and back, or restarting the PC.
read more →

Device-Code Phishing Uses OAuth to Bypass Microsoft 365

🔐 Researchers at KnowBe4 discovered a campaign aimed at North American businesses that tricks employees into entering a “Secure Authorization” code on a legitimate Microsoft 365 login page. Unknown to victims, the code actually authorizes an attacker-controlled device through the OAuth 2.0 Device Authorization Grant, issuing access and refresh tokens that grant persistent access to Outlook, Teams, OneDrive and other services. Recommended mitigations include allowlisting OAuth apps, disabling device-code flow in Entra conditional access where feasible, auditing integrations, and ongoing employee awareness training.
read more →

Windows Admin Center: Microsoft Patches Privilege Bug

🔒 Microsoft disclosed and patched a high-severity flaw in Windows Admin Center that could allow an attacker to escalate privileges. Tracked as CVE-2026-26119 with a CVSS score of 8.8, Microsoft credited Semperis researcher Andrea Pierini and included the fix in Windows Admin Center version 2511 (Dec 2025). The vendor described the issue as improper authentication and tagged it as Exploitation More Likely; technical details are currently restricted. Administrators are advised to apply the update promptly and restrict access to the management endpoint.
read more →

Budget Bytes: Build AI Applications on Azure for $25

💡Budget Bytes is a new video series that shows developers how to build production-quality AI applications on Azure for under $25. Each episode walks through end-to-end scenarios using the Azure SQL Database Free Offer, with live cost tallies, authentic debugging, and complete GitHub repos you can deploy yourself. Expect practical patterns and demonstrations of tools like Microsoft Foundry, Copilot Studio, and the Model Context Protocol, plus links to Microsoft Learn for deeper dives.
read more →

Establishing Proactive Defense with Exposure Management

📘 Microsoft published a new e-book, Establishing proactive defense—A maturity-based guide for adopting a dynamic, risk-based approach to exposure management, that helps security teams move from fragmented, reactive practices to a unified, risk-driven exposure management model. The guide describes five maturity levels, common pain points, and practical next steps to prioritize and verify mitigations. It is intended for security leaders seeking to turn telemetry into measurable risk reduction.
read more →

Running OpenClaw Safely: Identity, Isolation, Runtime

🔒 Self-hosted agent runtimes such as OpenClaw shift the execution boundary by ingesting untrusted text, downloading third‑party skills, and acting with the host's credentials. This combination makes the runtime effectively untrusted code execution with persistent tokens and elevated access, unsuitable for standard workstations. Microsoft recommends evaluating OpenClaw only in isolated VMs or dedicated devices, using dedicated non‑privileged credentials, continuous monitoring, and a fast rebuild plan. Prioritize containment, least privilege, and monitoring with solutions like Microsoft Defender XDR.
read more →