< ciso
brief />
Tag Banner

All news with #microsoft tag

1056 articles · page 8 of 53

Microsoft Patch Tuesday — August 2026 Update Summary

🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →

Microsoft patches 398 vulnerabilities, including active zero-day

🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
read more →

Windows 10 KB5120249 August 2026 Patch Update

🛡️ Microsoft released the Windows 10 KB5120249 Extended Security Updates (ESU) for 22H2 and 21H2, delivering the August 2026 Patch Tuesday fixes. The update is mandatory and raises OS Builds to 19045.7663 and 19044.7663. Install via Start > Settings > Update & Security > Windows Update or download from the Microsoft Update Catalog. The patch resolves a File History SMB backup failure and expands rollout of new Secure Boot certificates.
read more →

Windows 11 August 2026 cumulative updates released

🔔 Microsoft released Windows 11 cumulative updates KB512103 and KB5120240 for 25H2/24H2 and 23H2 to address security flaws, fix bugs, and add features. These August 2026 Patch Tuesday updates include fixes for roughly 400 vulnerabilities and are delivered via Windows Update or the Microsoft Update Catalog. Notable additions include improved Windows Search typo handling, Voice Access enhancements, touchpad gestures, and extended Windows Hello ESS support for peripheral fingerprint sensors.
read more →

AI-assisted exploit lets attackers assume SharePoint users

🔒 Security researchers discovered an unauthenticated bypass in Microsoft SharePoint allowing an attacker to impersonate any user, including administrators. The flaw, CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not listed. Rapid7 chained the bypass to an RCE, CVE-2026-63520, to run code as the Windows service account, and published analysis and a proof-of-concept. Organizations should ensure the July update is applied and watch for August patches.
read more →

DeadLock ransomware leverages blockchain for resilience

🛡️ Microsoft and security vendors observed DeadLock using decentralized services and an interactive HTML recovery chat to maintain extortion and data-leak operations without traditional backend infrastructure. The group, active since July 2025, uses Session messaging, Polygon smart contracts for proxy rotation, and blockchain-hosted leak content while employing selective encryption, hybrid crypto, and anti-forensic measures. Multiple actors have deployed it and it has claimed nearly 100 victims across Europe and the U.S.
read more →

CISA: SharePoint RCE Flaw Now Used in Ransomware

🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
read more →

Microsoft Named Leader in 2026 MDR/MXDR Report

🔒 Microsoft announced it was named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise. Microsoft Defender Experts MDR is a 24/7 managed detection and response service that operates natively on Microsoft Defender, combining global threat intelligence, AI-assisted workflows, and human experts. The service emphasizes continuous detection improvements, proactive hunting, and clear incident reporting to extend customer SOC capabilities.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

Microsoft 365 AitM Phishing Targets Payroll Workflows

🔍 Arctic Wolf Labs warns of a widespread email-driven phishing campaign using adversary-in-the-middle (AitM) techniques to seize Microsoft 365 sessions and harvest payroll and HR email. The campaign leverages residential proxies, multi-step redirections through trusted services, and fingerprinting scripts to evade filters and maintain compromised sessions at roughly eight-hour intervals. Affected sectors include healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
read more →

Microsoft named Leader in Gartner MQ for AI modernization

🚀 Microsoft has been named a Leader in the inaugural 2026 Gartner Magic Quadrant for AI-Augmented Code Modernization Tools, highlighting its agentic, AI-powered approach to speeding legacy modernization. Azure and GitHub Copilot modernization combine assessment, planning, and automated code and infrastructure upgrades while preserving human review and governance. Customers report large time and effort savings and rapid large-scale migrations.
read more →

Microsoft named a Leader in KuppingerCole CNAPP report

🔒 KuppingerCole’s 2026 Leadership Compass identifies a shift in CNAPPs toward unified platforms that secure cloud and AI workloads. The report names Microsoft a Leader across Overall, Product, Innovation, and Market for Defender for Cloud, citing its integrated approach to cloud, data, identity, and AI risk. The post highlights risk-based attack path analysis, AI security posture management, and agentic AI support for detection, prioritization, and remediation.
read more →

Kali365 Device-Code Phishing Threat to M365

🔒 Kali365 is a device-code phishing kit that abuses Microsoft's legitimate device login to gain persistent access to Microsoft 365 resources. The campaign primarily targets US organizations using SharePoint- and OneDrive-themed lures that redirect victims to Microsoft's real authentication portal where they enter attacker-supplied codes. Once access and refresh tokens are issued, attackers can maintain access to email, documents, and cloud assets, increasing risks of fraud, data exposure, and operational disruption. ANY.RUN telemetry links dozens of weekly sessions to this campaign and emphasizes rapid detection and contextual intelligence to contain token abuse.
read more →

Advancing Zero Trust for AI: New Tools and Guidance

🔒 Microsoft expands its Zero Trust for AI strategy with an automated Zero Trust Assessment and a new DevSecOps pillar in the Zero Trust Workshop to help organizations secure AI agents, developer workflows, and CI/CD pipelines. The Assessment evaluates tenant configuration and activity across Identity, Devices, Network, Data, AI, Security Operations, and Infrastructure, producing prioritized recommendations and executive-ready reports. The DevSecOps pillar maps Zero Trust principles into 15 control groups and 91 tasks covering source code, pipelines, dependencies, artifacts, and infrastructure-as-code. Together, the Assessment and Workshop convert findings into a phased 12–24 month remediation roadmap.
read more →

Microsoft Defender: Device Isolation Stops Ransomware Fast

🚨 Microsoft Defender’s attack disruption now includes device isolation, an automated response that isolates compromised endpoints. At QNET, Defender detected a multi-stage attack using mshta.exe and enforced isolation within 128 seconds, blocking a second-stage payload and preventing persistence or lateral movement. This action is AI-driven, time-limited, operator-controlled, and designed to work with user containment to reduce risk and speed SOC response.
read more →

RDS for SQL Server BYOM expands to 10 regions

📢 Amazon RDS for SQL Server now supports Bring Your Own Media (BYOM) in 10 additional commercial AWS Regions, including locations across Asia Pacific, Europe, and Mexico. BYOM lets customers reuse existing Microsoft SQL Server licenses with active Software Assurance via Microsoft's License Mobility program. The feature supports SQL Server 2019, 2022, and 2025 and integrates with AWS License Manager to track license usage and help maintain compliance. Availability and pricing vary by region.
read more →

Critical Cosmos DB flaw exposed master key risk

🛡️ A security researcher discovered a critical vulnerability in Azure Cosmos DB's Gremlin API that could have exposed the Cosmos Master Key, granting attackers read/write access to any Cosmos account and revealing database identifiers. Wiz, a Google subsidiary, disclosed the issue to Microsoft in November 2025; Microsoft pushed a hot fix within two days and later re-engineered the service to remove the master key and add guardrails. This follows a prior 2021 finding where Cosmos DB keys were exposed via a Jupyter Notebook flaw.
read more →

Microsoft Security: July 2026 innovations and updates

🔒 Microsoft announced new AI-native security capabilities across Defender, Entra, Purview, and Intune to help organizations secure AI environments, accelerate SecOps, and protect data and identities. Highlights include Project Perception, expanded Defender protections like prompt injection blocking, tenant governance and passkey defaults in Entra, Purview network-level DLP for shadow AI apps, and Intune Suite inclusion in Microsoft 365 E5 to strengthen endpoint management.
read more →

Russian hackers exploit Exchange OWA to hijack mailboxes

📧 A Russia-aligned group, tracked as TA488 (Void Blizzard/Laundry Bear), began a campaign on July 22 using a “half-click” exploit in Microsoft Exchange Outlook Web Access to install a browser-based backdoor when recipients viewed specially crafted emails. The attackers abused CVE-2026-42897, a cross-site scripting flaw allowing JavaScript to run inside OWA without clicking links or opening attachments. The implant, named OWAReaper, removes evidence from stored messages, harvests account data, and can leverage Outlook add-ins to obtain OAuth tokens and owner-level mailbox access, creating server-side persistence that typical endpoint-focused defenses may miss.
read more →