< ciso
brief />
Tag Banner

All news with #microsoft tag

1054 articles · page 3 of 53

Proof-of-Concept Fills Disk to Block Defender Updates

🛡️ A proof-of-concept named BigDiskBuster was published on GitHub on September 19 and prevents Microsoft Defender from installing platform and signature updates by filling all available disk space. The tool's author, former Microsoft researcher Abdelhamid Naceri, previously disclosed other Defender exploits that were used in live attacks. No patch, CVE, or official Microsoft advisory exists for this technique; administrators should monitor update failures, free space, and hidden temporary files while restricting execution of unknown binaries.
read more →

SharePoint flaw reclassified as remote code execution

🛡️ Microsoft initially labeled a SharePoint Server bug as a spoofing issue, but researcher Dinh Ho Anh Khoa's full disclosure shows it enables authenticated remote code execution. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition and was patched in August; the NVD assigns it an 8.8 score. Khoa's write-up details how unescaped quotes in Register directives allow arbitrary .NET class loading and execution via XamlServices.Parse().
read more →

Microsoft to retire Microsoft 365 companion apps

📰 Microsoft announced that it will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, and advised admins to remove them from managed devices. The company previously began auto-installing these taskbar-integrated apps on compatible Windows 11 enterprise devices with the Microsoft 365 desktop client. Admins could opt out via Device Configuration or users disable auto-launch in app settings. Microsoft has stopped installing the apps via Microsoft 365 Apps updates and asked unmanaged users to uninstall them.
read more →

Microsoft fixes Excel copy-and-paste bug for users

🛠️ Microsoft has issued fixes for an Excel paste failure introduced by September 2026 security updates that caused copy-and-paste, autofill, and formula dragging to fail silently in multiple Excel versions and Excel Online. Affected users must manually install specific updates for Excel 2016 and Office LTSC 2019, 2021, and 2024 to resolve the issue. Microsoft noted paste may still fail when workbooks contain conditional formatting and recommended using the Paste Special workaround (Ctrl+Alt+V) until a broader fix is available.
read more →

Microsoft September update breaks File History backups

🔔 Microsoft warned that the built-in File History backup feature may stop working on some systems after installing the September 2026 security updates. Affected users may see FileHistory.exe crashes referencing KERNELBASE.dll, incorrect "Reconnect your drive" prompts, stale "Last Backup" timestamps, and "No previous version available" for prior backups. Impacted releases include Windows 10 21H2+, Enterprise LTSC 2016/2019, and Windows 11 23H2+.
read more →

Microsoft Teams to allow custom blocked file types

🛡️ Microsoft Teams will let administrators customize the list of file extensions blocked by the built-in Weaponizable File Protection feature to align with organizational security policies. The capability is in development and slated to begin rolling out in November 2026 across Android, desktop, iOS, macOS, and web for standard multi-tenant cloud environments. Previously, admins could only rely on Microsoft’s default blocked file list. The change gives organizations greater flexibility to tailor file protection while preserving secure collaboration.
read more →

Microsoft patches CVSS 10.0 flaw in Azure AI Foundry

🔒 Microsoft has released a fix for a maximum-severity privilege escalation flaw in Azure AI Foundry (CVE-2026-85889, CVSS 10.0). The company says the issue, discovered by Rémy Marot, allowed missing authentication for a critical function but has been fully mitigated and requires no customer action. Microsoft also patched several other high-severity Azure and Windows vulnerabilities in recent updates.
read more →

Microsoft fixes false Defender Antivirus alerts

🔔 Microsoft resolved a bug that produced incorrect notifications stating Microsoft Defender Antivirus is turned off after recent updates. The fix was rolled out in the Microsoft Defender Antivirus update (version 4.18.26080.4) on September 17 and addresses alerts affecting supported Windows client and server releases. The erroneous messages appeared in the Windows Security app despite the antivirus functioning normally, and Microsoft has previously asked users to ignore similar false alerts from other updates.
read more →

Microsoft fixes Excel copy-and-paste bug for 2016

🛠️ Microsoft released a targeted update to address a code regression in KB5002914 that caused silent copy-and-paste, autofill, and formula dragging failures in Excel. The fix, KB5002655, applies only to the Microsoft Installer (.msi) edition of Office 2016, not Click-to-Run or Office 365 editions. Affected users can use Paste Special or uninstall the security update as temporary workarounds, though uninstalling removes important security patches.
read more →

Security Fundamentals to Reduce AI-era Cyber Risk

🔒 This post outlines Microsoft's Secure Now initiative within Microsoft Security Exposure Management, introduced May 2026, to help organizations prioritize foundational controls as AI accelerates threat complexity. It summarizes recent agentic and campaign-based incidents that show how familiar weaknesses—excessive permissions, unprotected authentication, unpatched systems—can chain rapidly into broader compromises. The blog maps practical mitigations, guided by Zero Trust, and highlights resources like FastTrack to operationalize continuous exposure reduction.
read more →

Microsoft Defender email security benchmarking updates

📈 This post summarizes Microsoft's latest quarterly email security benchmark covering May–July 2026 and highlights how continuous measurement improves prevention, detection, and adaptation. It reports Defender missed 221 high-severity threats per 1,000 users—55.4% fewer than the next closest SEG vendor—and notes Defender's 92% average post-delivery malicious catch. The report emphasizes evolving threat dynamics driven by AI and outlines Defender investments informed by telemetry and customer feedback.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft warned this week that Windows 11, version 24H2 Home and Pro editions will stop receiving security and preview updates on October 13, 2026. Under the company's lifecycle policy, Windows 11 24H2 Enterprise and Education editions remain supported until October 2027. Customers are advised to upgrade to Windows 11 25H2, which started rolling out via an enablement package in September 2024. Devices not managed by IT will be auto-upgraded but users can delay restarts.
read more →

Microsoft issues workaround for Windows domain login bug

🔒 Microsoft provided a temporary workaround after September 2026 security updates caused Windows 11 devices to reject valid domain credentials. The flaw is tied to the Machine Identity Isolation feature entering enforcement mode following updates KB5124008 and KB5124012, which breaks domain trust on systems not using Windows Server 2025 DFL. Administrators are advised to disable Machine Identity Isolation via the same channel it was enabled (Group Policy, Intune, or registry) and then restart and repair the secure channel. Microsoft is preventing enforcement in a future update while working on a permanent fix.
read more →

Windows 11 update breaks domain trust for some

🔒 Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust on some enterprise systems, preventing valid domain logins. Administrators report that affected devices lose their secure channel with Active Directory after reboot and observed Kerberos and NTLM failures. The issue may be linked to the Machine Identity Isolation setting, especially when set to enforcement mode, and some have restored access by adjusting registry values and repairing the secure channel.
read more →

LinkedIn Pushes Limits on Secrecy in Government Subpoenas

🛡️ Microsoft’s chief legal officer argued that secrecy orders accompanying government subpoenas should be the exception, not the rule. LinkedIn, owned by Microsoft, is challenging broad government demands that bar notifying customers when their data is sought, urging courts to impose meaningful limits and oversight. The company acknowledged law enforcement needs while asserting providers and users deserve adversarial review and notice. Legislative reforms in the House aim to constrain secrecy orders and strengthen notice protections.
read more →

Browser extension can hijack built‑in AI agents

🔒 Security researchers at Forever Security demonstrated that a single ordinary browser extension can commandeer built‑in AI assistants in five Chromium‑based products: Chrome (Gemini Live), Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. The exploit required only two common permissions and let the extension inject code into the trusted AI page to send commands to the agent. Google and Microsoft have issued patches for Chrome and Edge; Perplexity, Opera and Anthropic paid bounties but have not publicly fixed the exact methods described. Forever Security emphasized the attacks are proof‑of‑concepts requiring the malicious extension to be already installed.
read more →

Windows Server 2022 to leave mainstream support

🔔 Microsoft confirmed that Windows Server 2022 will reach end of mainstream support on October 13, 2026, and then transition into extended support through October 14, 2031. The October 2026 security update will be the last release under mainstream support. Hotpatching for Datacenter: Azure Edition is extended until October 2027. Administrators are advised to plan upgrades to Windows Server 2025 to remain fully supported.
read more →

Microsoft September Patch Breaks Excel Copy/Paste

🛠️ Microsoft confirmed that the September 2026 KB5002914 security update can cause copy-and-paste, autofill, and formula dragging to silently fail in Excel. Affected versions include Microsoft Excel 2016, 2019, 2021, and 2024, and users receive no error when the paste operation does not complete. Microsoft is investigating and will update its support document; some users report uninstalling KB5002914 restores functionality. The article also notes related recent Office and Windows fixes and emergency out-of-band updates.
read more →

Microsoft issues emergency out-of-band security patch

🛠️ Microsoft released an out-of-band update (KB5129195) on September 14 to address stability and functionality problems introduced by the September 8 Patch Tuesday. Affected services included Remote Desktop Services (RDS), MMC tools, File Explorer and the Windows Update page, which could become unresponsive or cause RDP connections to fail. The update also resolves Hyper-V issues impacting Plan9 shared folders, WSL integrations, and USB Audio Class 1.0 device failures. Administrators who applied temporary Group Policy mitigations do not need additional steps before installing this cumulative update.
read more →

Microsoft issues emergency Windows updates for RDS failures

🔧 Microsoft released out-of-band Windows updates on September 14 to address Remote Desktop Services (RDS) failures and related component crashes introduced by the September security updates. The fixes include updates for Windows 11 (KB5129194, KB5129195), Windows 10 (KB5129236), and Windows Server (KB5129235, KB5129237), and are available via Windows Update, WSUS, and the Microsoft Update Catalog. The Windows 11 updates also resolve a Hyper-V Plan9 share issue and some USB Audio Class 1.0 multichannel problems, though Microsoft is still working on remaining audio bugs.
read more →