< ciso
brief />
Tag Banner

All news with #microsoft tag

942 articles · page 4 of 48

Microsoft 365 outage disrupts Teams and SharePoint

🔔 Microsoft Teams and several Microsoft 365 services experienced an outage on July 23, with users reporting access problems for Teams, SharePoint, Excel, and the Microsoft 365 Admin Center. Downdetector recorded 2,403 reports at 11:11 a.m. ET, well above the normal baseline. SharePoint drove most complaints (78%), followed by Excel (11%) and the Admin Center (6%). Microsoft acknowledged the disruption, citing incident MO1437424 and stating it is investigating.
read more →

Email Threat Landscape Q2 2026: Key Findings

📊 Microsoft reports that Q2 2026 saw a sharp decline in phishing tied to the Tycoon2FA PhaaS disruption, while threat actors shifted tactics into Teams-based social engineering and vishing. Credential phishing remained the dominant payload objective, and notable campaigns demonstrated large-scale automation and multi-stage delivery chains. The post reviews QR code and CAPTCHA-gated phishing trends, BEC anomalies, and mitigation recommendations.
read more →

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

Microsoft’s three-day patching guidance raises risks

🛡️ Microsoft advises Windows administrators to apply security patches within three days, arguing that AI has accelerated vulnerability discovery and exploitation. Many enterprise teams, however, say the blanket three-day window is unrealistic given heavy testing, change control, and compatibility constraints. Experts recommend focusing rapid remediation on vulnerabilities with verified exploitation or credible proof-of-concept while using compensating controls and automation to manage broader exposure.
read more →

Microsoft and AXA XL Enhance Incident Response

🔒 Microsoft and AXA XL have partnered to provide AXA XL policyholders direct access to Microsoft Defender Experts Cybersecurity Incident Response, aligning technical, legal, and insurance workflows during incidents. The collaboration emphasizes pre-established coordination, proactive planning, and first‑party threat intelligence to accelerate containment and recovery. Together they aim to reduce friction and delays in high‑stakes cyber events.
read more →

Microsoft Ends Exchange 2016/2019 ESU Support in October

📢 Microsoft confirmed it will stop shipping security updates for Exchange Server 2016 and Exchange Server 2019 under the Extended Security Update (ESU) program in October 2026. The announcement follows a six-month extension granted in April 2026 and reiterates there will be no further extensions. Administrators are urged to upgrade to Exchange Server Subscription Edition or migrate to Exchange Online.
read more →

Invisible PR comment lets Azure DevOps AI abuse access

🛡️ A hidden HTML comment in an Azure DevOps pull request can instruct a reviewer's AI coding agent to act beyond an attacker's privileges, leaking sensitive data. The flaw exists because the MCP server returns PR descriptions without the spotlighting guardrail applied elsewhere, so the agent receives hidden instructions the human reviewer cannot see. Manifold Security demonstrated a proof-of-concept that chains permitted agent calls to read cross-project resources and exfiltrate content using reviewer credentials. Microsoft acknowledged the report and recommended limiting project access and reviewing changes before running AI tools.
read more →

Critical SharePoint RCE Exploited to Steal Machine Keys

🔒 Microsoft SharePoint's critical CVE-2026-50522 vulnerability is being actively exploited in the wild to steal machine keys and preserve access post-patch. Researchers observed attackers leveraging a public proof-of-concept to trigger deserialization-based remote code execution against on-premises SharePoint, allowing creation of forged authentication tokens. Microsoft fixed the flaw in July, but security firms advise rotating exposed credentials and confirming patches.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation

🛡️ Microsoft patched a critical SharePoint Server deserialization flaw, CVE-2026-50522 (CVSS 9.8), which is now being actively exploited. DEVCORE researcher splitline reported the issue; Microsoft warned authenticated attackers with Site Owner privileges could execute remote code. Security firms and CISA observed attackers stealing machine keys and urged credential rotation even after patching.
read more →

Microsoft issues WSUS sync fix and manual mitigation

🛠️ Microsoft published manual steps to remediate a WSUS synchronization problem that causes Windows Update scans to fail or time out on affected servers. The issue affects client (Windows 10, v1607+) and server (Windows Server 2012+) platforms and leads to prolonged sync times or operation timeouts due to accumulating publishing metadata. A service-side mitigation was rolled out for new or rebuilt WSUS installations, while administrators with existing servers are advised to back up SUSDB, run cleanup SQL queries, reset MaxXMLPerRequest, reindex SUSDB, run the WSUS Server Cleanup Wizard, and restart IIS or the WsusPool to restore normal sync behavior.
read more →

Unofficial patches available for LegacyHive zero-day

🛡️ Free unofficial micropatches are available for a recently disclosed Windows zero-day, dubbed LegacyHive, which enables non-admin users to escalate privileges by mounting other users' registry hives. The vulnerability was disclosed by researcher Nightmare Eclipse alongside a stripped proof-of-concept after Microsoft's July 2026 updates. ACROS Security (0Patch) offers free micropatches for affected Windows 10 2004+/Windows Server 2022+ systems; Microsoft says it is investigating the claims.
read more →

OneDrive and Google Drive for Multi‑Session Fleets

📂 Amazon WorkSpaces Applications now supports Microsoft OneDrive for Business and Google Drive as persistent storage options for multi-session fleets. Users streaming on shared fleet instances can connect their cloud accounts to access, save, and sync files directly within sessions, alongside the existing S3-backed home folder. This feature is available in all AWS Regions where WorkSpaces Applications is offered and incurs no extra charge beyond standard streaming usage pricing.
read more →

HollowGraph: Malware Using Microsoft 365 Calendar C2

🛡️ Group-IB discovered a .NET espionage implant called HollowGraph that uses a hijacked Microsoft 365 calendar as a covert command-and-control channel, reading operator instructions from a calendar event dated 2050-05-13 and exfiltrating stolen files as attachments. The implant uses the Microsoft Graph API to blend with legitimate traffic and avoids contacting attacker-owned servers directly. A secondary DNS-based channel supplies Entra ID client credentials via IPv6 AAAA records, written to a log file named logAzure.txt. Group-IB links the malware to the Cavern code family and recommends monitoring calendar events, application-driven Graph activity, and suspicious DNS AAAA queries.
read more →

Microsoft works to resolve WSUS sync delays

🛠️ Microsoft is addressing a known issue that has caused Windows Server Update Services (WSUS) servers to experience prolonged synchronization times and timeouts, impacting the delivery of updates. The problem, with heightened impact since July 13, 2026, affects client and server platforms and prevents admins from deploying updates through WSUS or Configuration Manager. Mitigations have been deployed for new or rebuilt WSUS installations, and Microsoft is developing additional steps to remediate previously affected servers.
read more →

Microsoft issues emergency fix for Dell shutdown bug

🛠️ Microsoft released out-of-band updates to address a compatibility issue that caused some Dell PCs to shut down or suffer performance and power problems after July 2026 Windows 11 updates. The bug stems from a June preview change to the Windows USB-C Connection Manager that conflicts with the Intel Innovation Platform Framework (IPF) Processor Participant driver, producing a yellow exclamation in Device Manager. Microsoft blocked the July update on affected systems and on Saturday shipped emergency updates KB5121767 and KB5121768 for Windows 11 25H2, 24H2 and Enterprise LTSC 2024 to resolve the issue. Managed devices with Autopatch will get the fix automatically, while Intune admins can accelerate deployment; affected users should restart after installation.
read more →

Microsoft warns of surge in ACR Stealer attacks

🛡️ Microsoft reports a marked increase in attacks leveraging ACR Stealer, an info-stealing MaaS that exfiltrates browser passwords, tokens, and sensitive documents from enterprise environments. Between late April and mid‑June, threat actors used social engineering (ClickFix), WebDAV servers, and mshta.exe to deliver obfuscated PowerShell loaders, Python-based installers, and in-memory payloads. The actor abuses GUID-based WebDAV paths, steganographic JPEGs, and public blockchains as dead-drop resolvers to mask activity and maintain C2 communications. Microsoft recommends filters, application control, and limiting access to unnecessary web resources to reduce exposure.
read more →

Microsoft at Black Hat USA 2026: Defending Trust

🔒 At Black Hat USA 2026, Microsoft Security highlights how threat actors exploit trusted systems—software, developer workflows, identities, and AI—to scale attacks. Sessions and briefings across August 4–6 focus on supply chain compromises, AI security, and practical defense strategies. Visit booth #2144 for demonstrations, expert-led services, and community events including a reception on August 5.
read more →

New LegacyHive Windows zero-day enables privilege escalation

🔒 A researcher known as Nightmare Eclipse published a proof-of-concept named LegacyHive after Microsoft's July 2026 Patch Tuesday, claiming it exploits a vulnerability in the Windows User Profile Service. The PoC has been intentionally modified to require additional credentials, making exploitation harder than earlier releases. Analysts note successful exploitation allows non-admin users to modify the classes registry hive and achieve code execution on admin login. Detection queries for Microsoft Defender for Endpoint were published shortly after.
read more →

Windows Server 2022 to leave mainstream support in 2026

📰 Microsoft has announced that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, and will transition to extended support with security updates through October 14, 2031. Customers are advised to plan upgrades to Windows Server 2025, the latest LTSC release available since November 2024. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and highlighted lifecycle resources for planning migrations.
read more →