< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 6 of 48

Microsoft trials cleaner, ad-free Windows Search

🔍 Microsoft is testing a faster, cleaner Windows Search experience for Insiders that emphasizes relevant local results over ads and promotional content. The update, announced by Windows search leads, is rolling out via the Experimental channel and Controlled Feature Rollout, with feature flags and a reboot check for access. Changes include clearer result sources, a setting to hide Store and web suggestions, improved two-character file search, better cloud-file visibility, and increased typo tolerance. Reliability fixes and additional improvements are coming soon.
read more →

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →

ModHeader removed after hidden browsing-history collector

🛡️ Google and Microsoft removed the popular ModHeader extension after researchers found a dormant browsing-history collector embedded in the official store builds. The collector, confirmed by Stripe OLT to be in the genuine Chrome package, stored encrypted domain lists and device fingerprints locally and was designed to upload them to api.stanfordstudies[.]com on a schedule if an internal allow-list were populated. While the allow-list shipped empty and no evidence shows data was exfiltrated, the extension still pinged extensions-hub[.]com and logged request metadata locally. Users are advised to uninstall ModHeader, rotate exposed secrets, and defenders should block the implicated domains and hunt for related indicators.
read more →

Microsoft makes passkeys default for Entra ID

🔒 Microsoft Entra ID will begin rolling out passkeys as the default phishing-resistant authentication method starting September 1, 2026. Users currently using SMS or voice for MFA will be auto-enabled for passkeys and prompted to register on their next sign-in. Microsoft will retire native SMS and voice delivery on February 1, 2027, after which telecom partners via the Microsoft Security Store will be required for those methods.
read more →

Microsoft Secure Future Initiative July 2026 Report

🔒 This progress report outlines Microsoft’s Secure Future Initiative (SFI) two-year effort to strengthen security foundations, apply AI for proactive defense, and prepare for future challenges such as post-quantum risks. It highlights layered controls—identity, access governance, segmentation, and secure engineering defaults—paired with cultural and governance measures to make protections durable. The report also shares lessons, practical guidance, and metrics of organizational adoption.
read more →

GigaWiper: Unified backdoor blends espionage and wiping

🛡️ Microsoft has identified GigaWiper, a versatile Golang backdoor that consolidates espionage and multiple destructive wiping capabilities into a single implant. The tool merges components from at least three prior malware families, enabling command-and-control, disk-level wiping, fake ransomware with unrecoverable keys, and multi-pass secure wiping. Researchers observed standalone wipers and larger backdoor binaries, and advise enabling tamper protection, cloud-delivered antivirus, EDR in block mode, and blocking known C2 infrastructure.
read more →

Microsoft warns of rising Windows security updates

🛡️ Microsoft says it is deploying AI-driven analysis to uncover more zero-day vulnerabilities across the Windows codebase, warning customers to expect an increased number of security updates. The company described a multi-model agentic scanning harness (MDASH) and a separate prove pipeline to validate findings, aiming to reduce false positives and shorten review windows. Microsoft also plans to update its Secure Development Lifecycle to address AI-enabled attack techniques while retaining human oversight to ensure update quality.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →

GPT-5.6 Available Now in Microsoft Foundry

🚀 Microsoft announces general availability of GPT-5.6 in Microsoft Foundry, integrating frontier models, production agent runtime, and enterprise controls into a single platform. The release includes Sol, Terra, and Luna model tiers with published pricing, Global and APAC Data Zone deployment options, and developer tooling for GitHub Copilot and VS Code. Foundry emphasizes observability, cost controls, and governance to accelerate production agent adoption.
read more →

Microsoft warns of more Windows security updates ahead

🛡️ Microsoft says AI-driven discovery is increasing the pace of vulnerability identification in Windows, leading to a likely rise in monthly security updates. The company uses its MDASH system to scan critical binaries and validate potential issues with multiple AI models, then runs a Windows-specific validation pipeline to reduce false positives. Microsoft also applies AI to accelerate triage, suggest fixes, and find similar bugs, while keeping humans in the review loop. The firm is updating its Secure Development Lifecycle to address AI-enabled attack techniques as adversaries also leverage AI.
read more →

Microsoft Foundry expands frontier models and agents

🚀 Microsoft announces general availability updates to Microsoft Foundry, combining frontier models, a production agent runtime, enterprise identity and security controls, and Microsoft 365 distribution into one platform. The release includes GPT-5.6 models across global regions and the new Asia-Pacific Data Zone for regional data processing. Developers can build in GitHub Copilot or VS Code and deploy agents using Foundry toolkits and SDKs.
read more →

Forg365 PhaaS Targets Microsoft 365 with AI

🛡️ Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device-code phishing with integrated AI-assisted lure generation. The service offers an admin dashboard for campaign management, OAuth and SMTP configuration, token handling, and a browser extension called ForgCookie for persistent cookie harvesting. Researchers at ZeroBEC found the operation uses legitimate delivery services like Amazon SES and SendGrid-hosted resources to blend malicious emails into normal traffic.
read more →

Microsoft to retire OWA Light from Exchange Server

📰 Microsoft will remove the OWA Light experience from on-premises Exchange Server in an upcoming update. The Exchange Team says retiring OWA Light reduces legacy surface area, simplifies engineering, and lets them focus on the full Outlook on the web experience. Administrators can proactively disable OWA Light via PowerShell using Set-OwaMailboxPolicy and Set-OwaVirtualDirectory commands. The change is expected in August 2026 after OWA Light was deprecated in August 2024.
read more →

Microsoft patches RoguePlanet Defender flaw

🛡️ Microsoft released a security update addressing a privilege escalation bug in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656. The issue, dubbed RoguePlanet, is a race condition that can allow an attacker to spawn a SYSTEM-level shell to run arbitrary code. The fix is included in engine version 1.1.26060.3008 and includes defense-in-depth hardening.
read more →

Microsoft patches Defender RoguePlanet zero‑day

🛡️ Microsoft released a Malware Protection Engine update to fix a Defender zero-day tracked as CVE-2026-50656, dubbed "RoguePlanet." The vulnerability, disclosed by researcher "Nightmare Eclipse," allows spawning a SYSTEM command prompt via a Defender race condition and reportedly works on fully patched Windows 10 and 11 devices. Microsoft shipped version 1.1.26060.3008 to address the issue after confirming work on a patch on June 16.
read more →

Microsoft details SFI AI system to harden cloud

🚀 Microsoft describes a multi-agent AI system within the Secure Future Initiative (SFI) that continuously evaluates and hardens its cloud services. The system combines code, configuration, identity, network, and runtime evidence to find composite vulnerabilities and assess layered defenses. It generates assurance trees tailored to each service and produces high-quality, actionable findings that speed remediation. Microsoft reports the system compresses deep security reviews from weeks to hours and that over 90% of findings were validated by engineers.
read more →

Fake Microsoft Teams support call scam targets files

📢 Palo Alto Networks’ Unit 42 warns of a new campaign targeting Microsoft Teams users that begins with a survey email and a malicious PDF. If opened, victims soon receive a voice call claiming to be Microsoft Support; the fake agent requests permission to install a remote access tool and additionally deploys Ether RAT. The Trojan gives attackers full access to the compromised machine, enabling theft of sensitive information and files. Users should be cautious of unsolicited surveys and support calls.
read more →

UK launches Cyber Resilience Pledge for businesses

🛡️ The UK government announced the Cyber Resilience Pledge, with over 60 businesses signing up after its unveiling at CYBERUK in April alongside a £90m support package. Signatories such as Microsoft UK, Marks & Spencer and Vodafone commit to board-level cyber accountability, NCSC training, Early Warning registration and risk-based Cyber Essentials adoption across supply chains. The scheme targets medium and large firms with the aim of driving baseline security improvements across suppliers.
read more →