< ciso
brief />
Tag Banner

All news with #microsoft tag

1054 articles · page 4 of 53

Microsoft September Patch Breaks Vulnerability Records

🔒 Microsoft’s September patch is unusually large, addressing a record ~972 vulnerabilities with 112 rated high critical. This follows consecutive months of escalating patch counts and coincides with industry concern over AI-accelerated discovery and exploitation of flaws. Vendors and organizations have warned the window for patching is narrowing, prompting a surge in rapid remediation efforts. Microsoft emphasizes immediate updates as attackers can quickly weaponize fixes through AI-assisted analysis.
read more →

Microsoft September updates cause RDS failures

🔔 Microsoft confirmed that its September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server and client systems. The issue affects Windows Server 2012 and later, as well as Windows 10 and Windows 11, producing RDP connection drops, sign-in problems, and unresponsive management tools. Microsoft published Group Policy mitigations for enterprise environments and noted temporary recovery by restarting affected VMs or uninstalling the updates, though removal also drops security fixes. The company is working on a permanent fix.
read more →

Microsoft September updates break USB audio on Windows

🔊 Microsoft confirmed that installing the KB5124008 and KB5124012 September 2026 security updates can cause some USB Audio Class 1.0 devices to fail on Windows 11 version 24H2 or later. Affected users report "This device cannot start (Code 10)" errors, no audio output, and unresponsive volume controls; some speakers fail only with multichannel or 3D audio. Microsoft has not provided an official workaround, though switching to 2-channel mode has restored audio for some users.
read more →

Threat Actors Use Passkey Phishing to Breach Cloud

🛡️ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more →

Microsoft redirects Teams and Copilot addresses

🔔 Microsoft is changing the destination addresses for two widely used services: Teams web users are being redirected to teams.cloud.microsoft and M365/Copilot web users to copilot.cloud.microsoft. Organizations should update network controls—client devices, proxies, firewalls, and secure web gateways—to ensure continued access and follow Microsoft’s recommended network requirements. Redirects are expected to complete by early October, with limited Teams exceptions until Dec. 31, 2026.
read more →

Phishing Abuse of Microsoft 365 Direct Send Peaks in US Hours

📧 KnowBe4 researchers observed a large-scale phishing campaign abusing Microsoft 365’s Direct Send feature, with 29,785 confirmed malicious emails sent during July and August 2026. The campaign followed US Eastern business hours, peaking Monday–Tuesday just before noon and again around 2pm EST. Attackers used Direct Send to spoof trusted internal senders and bypass some gateway protections, often including malicious attachments and reply-to addresses directing responses to attackers. The report recommends monitoring the Exchange header "X-MS-Exchange-Organization-AuthAs: Anonymous," enforcing DMARC p=reject, restricting Exchange Online connectors to approved IPs, closing unneeded Direct Send pathways, and enabling DKIM signing.
read more →

Passkey-Themed Scams Hijacking Microsoft 365 Accounts

🔒 Microsoft Security Research has tracked a campaign since May where attackers pose as IT helpdesk staff to trick employees into updating or enrolling a passkey. Victims are redirected to AiTM phishing pages or legitimate Microsoft device-code flows, enabling attackers to capture credentials and session tokens or authorize attacker-controlled clients. Compromised identities allowed adversaries to register their own authentication methods, use Microsoft Graph to map tenants, and exfiltrate files and email from SharePoint, OneDrive, and Exchange.
read more →

Microsoft fixes Teams and Outlook launch bug on ARM

🛠️ Microsoft patched a bug that blocked Teams and the new Outlook from launching on ARM-based Windows 11 devices after August 2026 updates. The issue affected devices such as Surface Pro 11 and Surface Laptop 7 that had not installed Microsoft Store updates, while classic Office apps were reportedly unaffected. Microsoft resolved the problem in the September 8, 2026 cumulative update (KB5124012) and advised users to install the latest updates.
read more →

Organizations Deploy AI Without Adequate Permissions Checks

🔍 A Syskit study finds rapid enterprise AI adoption on Microsoft 365 outpaces permission reviews and governance controls. 76% of organizations have deployed or piloted AI tools like Copilot, yet only 43% completed thorough permissions reviews before rollout. The survey highlights widespread misconfigurations, orphaned content and gaps in access reporting, leaving many environments exposed.
read more →

SageMaker Unified Studio gains ODBC for Power BI

🔗 Amazon SageMaker Unified Studio now supports ODBC connections, enabling Microsoft Power BI and other ODBC-compatible tools to connect directly to governed data using the Amazon Athena ODBC driver. The project overview page adds an ODBC connection details view alongside the existing JDBC view, providing DSN-less connection strings or parameters for named DSNs. The Athena ODBC driver (v2.2.0.1+) supports SageMakerBrowserIdc and SageMakerIam authentication modes. ODBC access is available today in all Regions where SageMaker Unified Studio is offered, at no additional cost.
read more →

Microsoft named Leader in 2026 container MQ

🚀 Microsoft reports being named a Leader in the 2026 Gartner® Magic Quadrant™ for Container Management, positioned furthest on Completeness of Vision. The post outlines how Azure's container portfolio—including AKS, Azure Container Apps, Azure Arc, and Azure Kubernetes Fleet Manager—supports diverse AI and application workloads across cloud, edge, and hybrid environments. It emphasizes open-source alignment with upstream Kubernetes and investments in operational automation and agentic operations to address cluster sprawl and governance challenges.
read more →

September Windows Server updates break RDS connectivity

🖥️ Administrators report that September 2026 cumulative updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025, preventing users from connecting and sometimes requiring hard resets. Affected servers often run normally for hours after patching before RDS connections start failing; existing sessions may not disconnect and new connections hang. Rolling back the updates restores functionality, but also removes security fixes. Microsoft is aware and investigating.
read more →

Excel KB5002914 update disrupts copy and paste

🔧 Users report that Microsoft’s KB5002914 Office security update, released in the September 2026 Patch Tuesday, is breaking copy-and-paste and formula autofill in Excel for some installations. Affected reports span Office versions from 2016 through 2024 and include both MSI and Click-to-Run deployments. Uninstalling or rolling back the update restores functionality for many users, while Microsoft says it is investigating and has added the issue to the KB5002914 release notes.
read more →

Cloud Web Applications Threat Matrix Overview

🛡️ Microsoft introduces a MITRE ATT&CK-aligned Cloud web applications threat matrix to help defenders map and prioritize threats against cloud-hosted web apps and serverless platforms. The framework organizes attack techniques across application code, managed runtimes, identities, deployment pipelines, and connected cloud resources to surface cross-layer attack paths. The blog describes selected techniques and actionable defensive priorities to reduce exposure in cloud-native environments.
read more →

Passkey-Themed Social Engineering Drives Cloud Identity Compromise

🔒 Microsoft Security Research describes coordinated intrusions beginning with passkey-themed social engineering and progressing to authentication persistence, cloud reconnaissance, and targeted data collection. The actors use phone and trusted internal messages to lure victims to convincing phishing sites or device-code flows, then add authentication methods and leverage Microsoft Graph, SharePoint, OneDrive, and Exchange to enumerate and collect data. Defenders are urged to investigate identity and Microsoft Graph signals, revoke sessions, and remove unauthorized auth methods.
read more →

Microsoft September Patch Tuesday Sets New Record

🛡️ Microsoft released a record 974 CVE fixes in its September 2026 Patch Tuesday, far surpassing the previous monthly high of 570. The update affects a broad range of products, with Windows accounting for 723 CVEs and Office 111. Microsoft highlighted two actively exploited zero-days and the bundle includes 119 critical vulnerabilities, prompting calls for a risk-based approach to prioritization.
read more →

Researcher Releases PoC for Microsoft Defender Zero-Day

🛡️ A researcher known as Chaotic Eclipse published a proof-of-concept for a zero-day in Microsoft Defender, dubbed ShieldCrash. The bug is described as a patch bypass for CVE-2026-69414 (ShieldBreak), which the researcher reported last month. The PoC shows an arbitrary file read as SYSTEM on up-to-date Windows installations, with all supported desktop versions affected. Microsoft recently updated the Malware Protection Engine to address CVE-2026-69414 and urges automatic updates for protection.
read more →

Microsoft issues record Patch Tuesday fixes

🛡️ Microsoft released an unprecedented Patch Tuesday fixing 974 vulnerabilities across its product portfolio, including two actively exploited zero-days. The updates span Windows, Office, SQL Server, and developer tools, with over 110 rated critical and many tied to privilege escalation, remote code execution, and information disclosure. CISA added the two exploited flaws to its KEV catalog, mandating federal remediation by September 22, 2026.
read more →

Microsoft Patch Tuesday: September 2026 Vulnerabilities

🔒 Microsoft released its September 2026 security update covering 973 vulnerabilities across many products, including 113 marked critical. Two vulnerabilities were reported exploited in the wild: one in the Windows Update Stack (CVE-2026-81963) and one in Windows ALPC (CVE-2026-85880). The bulletin highlights numerous remote code execution and elevation-of-privilege issues, with several high CVSS scores and multiple components prioritized for remediation.
read more →

Microsoft issues record Windows security patch batch

🔒 Microsoft released updates addressing at least 974 security vulnerabilities across Windows and other products, its largest single patch bundle ever. Two zero-day vulnerabilities are being actively exploited, and 113 bugs were rated critical. Vendors attribute rising patch volumes to AI-assisted discovery, while security teams warn of the burden of testing and deploying so many fixes. Administrators are urged to prioritize and test patches carefully to avoid disruption.
read more →