< ciso
brief />
Tag Banner

All news with #microsoft tag

942 articles · page 5 of 48

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

CISA urges immediate SharePoint hardening now

🔒 CISA has warned that three Microsoft SharePoint vulnerabilities are being actively exploited and urged organizations to immediately patch on-premises SharePoint deployments. Administrators should follow Microsoft’s mitigation guidance, enable AMSI integration, hunt for indicators of compromise, and rotate machine keys where appropriate. The agency added CVE-2026-33201, CVE-2026-45659, and the newly listed CVE-2026-56164 to its Known Exploited Vulnerabilities catalog and required rapid remediation for federal agencies.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft announced that Windows 11 version 24H2 Home and Pro editions and Windows 10 Enterprise LTSB 2016 will stop receiving monthly updates after October 13, 2026. Enterprise and Education editions remain supported until October 12, 2027. Users are advised to upgrade to Windows 11 25H2, which is available via an enablement package and will be offered automatically to unmanaged Home and Pro devices. Devices can defer the update or choose restart timing through Settings > Windows Update.
read more →

Microsoft July 2026 Patch Tuesday: 570+ Vulnerabilities

🔒 July’s Patch Tuesday from Microsoft addressed an unprecedented number of vulnerabilities, with reports of 570–622 CVEs (620 if platform-level fixes are counted), plus hundreds in Chromium. The release includes many high-severity flaws — notably elevation of privilege and remote code execution bugs — with only three zero-days and 59 critical issues. Microsoft’s new summary-style advisories and its AI-powered MDASH scanning explain the surge, forcing organizations to reassess patch management and prioritization.
read more →

Defender Experts Close the Intelligence‑to‑Action Gap

🛡️ Microsoft announces Defender Experts Threat Intelligence and expands Defender Experts MDR to include third-party and multi-cloud coverage. The expert-led services translate global signals into prioritized, environment-specific guidance and integrate Microsoft Defender Threat Intelligence into the Defender portal for real-time use across detection, investigation, response, and hunting. Defender Experts MDR Plan 2 extends managed detection and response beyond Microsoft products using Microsoft Sentinel, enabling experts to follow threats across heterogeneous estates. These offerings aim to shorten the time from signal to decisive action and will be showcased at Black Hat.
read more →

Microsoft‑signed UEFI shims allow Secure Boot bypass

🛡️ ESET found 11 Microsoft-signed UEFI shim bootloaders (version 0.9 or earlier) contain vulnerabilities that enable Secure Boot bypass across many systems. These shims trust outdated second-stage loaders like older GRUB 2 builds, allowing unsigned kernels or bootkits to load even with Secure Boot enabled. Microsoft issued dbx revocations on June 9; Windows will update automatically and Linux users should fetch revocations via the Linux Vendor Firmware Service. ESET cautions defenders to follow protection guidance rather than rely on IoCs.
read more →

CISA warns: patch actively exploited SharePoint flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) in Internet-exposed on-premises instances. The flaws enable authentication bypass, remote code execution, and post-exploitation activity including theft of IIS machine keys and persistence to deploy malware. CISA urged administrators to apply Microsoft's patches, verify installation, shorten patch cycles, enable AMSI integration for SharePoint, use Microsoft Defender Antivirus detections, and implement hardening and monitoring measures.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

Microsoft blocks update for Dell devices after shutdowns

🛠️ Microsoft is blocking the June Windows 11 update on some Dell systems after the KB5095093 preview update introduced an incompatibility with the Intel Innovation Platform Framework Processor Participant driver. Affected devices may show a yellow exclamation in Device Manager and experience unexpected shutdowns, poor performance, overheating, and battery drain. Microsoft is working with Dell and will pause KB5101650 distribution until a fix is released in the coming days.
read more →

Microsoft July 2026 Patch Tuesday: 622 Flaws Released

🛡️ Microsoft released its July 2026 security updates addressing 622 vulnerabilities across many products, including 57 marked critical. Two flaws have confirmed in-the-wild exploitation: an AD FS elevation of privilege (CVE-2026-56155) and a SharePoint spoofing/authentication issue (CVE-2026-56164). Talos highlights multiple critical remote-code-execution and elevation-of-privilege flaws affecting Windows components, Office, SharePoint, SQL Server, Defender, Copilot and cloud services. Cisco Talos also published Snort rules and urged customers to update intrusion-detection rule sets to detect exploitation attempts.
read more →

Microsoft ships record July Patch Tuesday fixes

🔒 Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs including two actively exploited elevation-of-privilege flaws in on‑premises SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint bug allows unauthenticated network privilege escalation and is tied to incident responders at Mandiant and Google's FLARE; admins should patch immediately and consider enabling AMSI Full Mode. The AD FS bug permits local privilege escalation for authenticated users and was credited to Microsoft DART. A third disclosed BitLocker bypass (CVE-2026-50661) requires physical access and is lower priority. The update also finalizes Kerberos RC4 hardening, risking authentication breaks for service accounts still using RC4 unless audited and rotated first. Microsoft says AI tooling increased bug discovery, and the scale of fixes means organizations should prioritize by exploitation status rather than CVSS score.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Microsoft issues Windows 10 KB5099539 security update

🔒 Microsoft released the Windows 10 KB5099539 extended security update, delivering the July 2026 Patch Tuesday fixes and additional security and reliability improvements for enrolled devices and LTSC editions. The update moves Windows 10 to build 19045.7548 (19044.7548 for Enterprise LTSC 2021) and addresses a record 570 vulnerabilities, including two exploited and one publicly disclosed zero-day. Administrators and eligible consumers can install it via Settings > Windows Update; several known issues and hardening changes are documented.
read more →

Windows 11 July 2026 Cumulative Updates Released

🛈 Microsoft released Windows 11 cumulative updates KB5101650 and KB5099414 for 25H2/24H2 and 23H2 to deliver July 2026 Patch Tuesday fixes addressing security vulnerabilities, bug fixes, and feature refinements. The rollouts update build numbers and include notable Bluetooth pairing improvements, a quieter Widgets experience, enhanced accessibility controls, File Explorer and networking fixes, and Point-in-Time restore availability. Install via Settings > Windows Update or the Microsoft Update Catalog.
read more →

Old Microsoft-signed UEFI shims expose Secure Boot

🔒 Researchers found 11 Microsoft-signed UEFI shim bootloaders that can be abused to bypass Secure Boot on many systems, enabling execution of untrusted code during early boot. ESET and CERT/CC detail how outdated shims (mostly v0.9 and earlier) remained trusted because they were not revoked, allowing attackers to deploy UEFI bootkits and persist below the OS. Microsoft revoked affected certificates in June 2026 following disclosures.
read more →

Microsoft trials cleaner, ad-free Windows Search

🔍 Microsoft is testing a faster, cleaner Windows Search experience for Insiders that emphasizes relevant local results over ads and promotional content. The update, announced by Windows search leads, is rolling out via the Experimental channel and Controlled Feature Rollout, with feature flags and a reboot check for access. Changes include clearer result sources, a setting to hide Store and web suggestions, improved two-character file search, better cloud-file visibility, and increased typo tolerance. Reliability fixes and additional improvements are coming soon.
read more →

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →