< ciso
brief />
Tag Banner

All news with #microsoft tag

1056 articles · page 7 of 53

Critical Windows IKE Extension Flaw Actively Exploited

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are exploiting a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824. The vulnerability affects supported Windows 10, Windows 11, and Windows Server versions and can be triggered by unauthenticated attackers sending crafted packets to UDP ports 500 or 4500. Microsoft issued a Patch Tuesday advisory and recommended firewall mitigations for organizations that cannot immediately apply updates.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft warned that Windows 11 version 24H2 Home and Pro editions will stop receiving security and preview updates on October 13, 2026. Enterprise and Education editions of 24H2 remain supported until October 2027, and Microsoft recommends upgrading to Windows 11 25H2, widely available since September 2024. unmanaged Home and Pro devices will auto-upgrade to 25H2, though users can postpone restarts; administrators should use Settings > Windows Update to check availability.
read more →

Microsoft tests faster File Explorer and context menu

🖱️ Microsoft is rolling out Windows 11 preview builds to Insiders that test a faster File Explorer and a streamlined, customizable context menu. The update reduces top-level clutter, improves performance and reliability, and adds a "Customize menu" shortcut to Settings for tailoring right-click options. The team says refinements also address customer feedback such as uninterrupted file renames and immediate case-only filename updates.
read more →

Microsoft addresses Microsoft 365 search outage bug

🔎 Microsoft reported that some users experienced search failures across Microsoft 365 services including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. An internal incident (MO1456424) traced the problem to a recent deployment that caused resource utilization inefficiencies on affected infrastructure. Microsoft said it developed and deployed a fix to reduce resource pressure and restore service for impacted users. The company has not disclosed which regions were affected but categorized the event as an incident.
read more →

Microsoft removes WMIC from Windows 11 beta builds

🛡️ Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2 and recent beta builds as part of its planned deprecation. The company previously converted WMIC to a Feature on Demand and announced its eventual removal; WMI itself remains available. IT administrators are advised to migrate scripts to PowerShell, WMI COM APIs, .NET libraries or other modern tools. The change aims to reduce abuse of WMIC as a LOLBIN used by attackers for ransomware, evasion, and other malicious activities.
read more →

Amazon Quick Microsoft 365 Extensions Now GA

🚀 Amazon Quick announces general availability of Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook, enabling AI-driven tasks directly within users' M365 environments. The Excel extension assists with advanced analysis, pivot tables, charts, and data cleaning. PowerPoint and Word extensions generate and format presentation decks and documents using organization templates and track changes. The Outlook extension helps prioritize emails, organize inboxes, schedule meetings, and draft replies using Quick data and full inbox context.
read more →

Microsoft named a Leader in Gartner MQ 2026

🔷 Microsoft was named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms, marking its third consecutive year in that quadrant. The post highlights how Azure’s platform consolidates application modernization, AI toolchains, operations, and security into a single foundation. It describes services like Azure App Service, Container Apps, Azure Functions, and API Management as core components enabling production AI workloads and agentic applications. Customer examples illustrate real-world production usage and operational impact.
read more →

Certighost: Privilege Risks in Your Certificate Authority

🔒 Certighost (CVE-2026-54121) demonstrates how a standard domain user can coerce an Enterprise CA to issue a Domain Controller certificate via AD CS "chase" behavior. The flaw allows an attacker to obtain PKINIT authentication as a DC, perform DCSync, and escalate to domain compromise. Microsoft patched the issue on July 14, 2026; mitigate by patching, restricting CA outbound access, and reducing MachineAccountQuota.
read more →

Windows Server 2022 Approaches Mainstream End Date

📢 Microsoft reminded administrators that Windows Server 2022 will reach end of mainstream support on October 13, 2026, and will transition to extended support with monthly security updates through October 14, 2031. The company urged customers to plan upgrades to Windows Server 2025, available since November 2024, and to begin deployment testing early. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and noted related lifecycle dates for other products.
read more →

Microsoft works on patch for Defender ShieldBreak zero-day

🛡️ Microsoft confirmed it is developing a security update to address a new Microsoft Defender zero-day called "ShieldBreak," disclosed by researcher "Nightmare Eclipse" after the August 2026 Patch Tuesday. The PoC reportedly allows local attackers with limited permissions to escalate to SYSTEM on patched Windows 10, Windows 11, and Windows Server, and has been tracked as CVE-2026-69414. Microsoft stated it is investigating and will provide a quality security update, while the researcher publicly disclosed the exploit amid a dispute over disclosure and bounties.
read more →

Amazon Quick Microsoft 365 Extensions Now Generally Available

🔔 Amazon Quick has made Microsoft 365 extensions for Excel, PowerPoint, Word, and Outlook generally available. These extensions let Quick operate directly inside users' M365 environments to handle complex local tasks, including document redlining, financial model building, presentation creation, and inbox management. Each extension is tailored: Excel for data analysis and cleaning, PowerPoint for template-driven decks, Word for formatted drafting and track changes, and Outlook for prioritizing, organizing, and drafting emails. The extensions are available in multiple AWS regions globally.
read more →

Microsoft patches LegacyHive Windows zero‑day

🛡️ Microsoft released patches addressing the Windows zero-day dubbed LegacyHive, disclosed after July 2026 Patch Tuesday. The flaw was revealed by a researcher using the "Nightmare Eclipse" handle, who published a proof-of-concept after the updates; the exploit requires additional credentials, limiting easy weaponization. Microsoft tracked the issue as CVE-2026-62832 and describes the bug as improper link resolution in the Windows User Profile Service that can allow local privilege escalation. ACROS Security also issued unofficial mitigations prior to Microsoft's August fixes.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Rethinking cyber defense as AI accelerates exploits

🔒 Microsoft warns that AI-driven tools are accelerating vulnerability discovery and exploit generation, making traditional reactive patching and detection-centric defenses insufficient. David Weston of Microsoft highlighted MDASH findings showing rapid, low-cost exploit generation and urged industry shifts toward memory-safe languages like Rust, proactive secure-by-construction methods, and AI-assisted remediation. The talk, delivered at Black Hat USA, framed resilience and prevention as the new priorities.
read more →

Researcher posts Defender patch bypass PoC

🛡️ A researcher known as Nightmare Eclipse published a proof-of-concept called ShieldBreak that appears to bypass Microsoft’s recent patch for CVE-2026-50656, enabling attackers with any initial access to escalate to system-level privileges. Security experts warn the PoC could erode trust in patches and stress defense-in-depth measures such as application allowlisting, tightened admin rights, and hunting for MsMpEng.exe spawning system shells. Independent confirmations and community detections are emerging, though Microsoft has not yet provided a formal response.
read more →

Managing AI Spend with Agent Optimization

🧭 This post introduces a four-part series, The Economics of Agent Optimization, explaining how organizations can run AI as a managed investment system using Microsoft Foundry. It argues that cost discipline—not just model choice—determines whether pilots scale, and outlines the need for visibility, controls, and workflow optimization to manage token-driven spend. The piece positions Foundry and Microsoft Agent 365 as integrated solutions for cost attribution, runtime optimization, and continuous governance.
read more →

PoC for SharePoint JWT Bypass Now Used in Attacks

🔒 A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more →

New ShieldBreak zero-day elevates Defender privileges

🔒 A new zero-day named ShieldBreak was published by researcher Nightmare Eclipse after Microsoft's August 2026 Patch Tuesday. The exploit is a bypass for the earlier RoguePlanet privilege escalation flaw and can grant SYSTEM privileges on patched Windows 10, Windows 11, and Windows Server installations. The researcher claims a 100% success rate in tested builds and ties the release to an ongoing dispute over Microsoft's disclosure and bug bounty practices.
read more →

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →