< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 8 of 48

Operation Endgame disrupts Amadey and StealC malware

🔎 Microsoft, Europol, and international partners executed Operation Endgame to disrupt infrastructure used by the Amadey and StealC malware families. The coordinated takedown targeted servers, domains, and related resources, seizing cryptocurrency and recovering millions of stolen credentials. Private-sector partners including Microsoft, ESET, Proofpoint, and IBM X-Force supported law enforcement actions across several countries. The effort also targeted SocGholish loaders and follows prior phases that disrupted other malware families.
read more →

StealC and Amadey: Infostealer Ecosystem Disruption

🔍 Microsoft analyzes how infostealers like StealC and loaders such as Amadey fuel a commodified cybercrime economy by harvesting credentials, cookies, and tokens from unmanaged devices. The post details methods of delivery (SEO poisoning, malicious ads, ClickFix, phishing), StealC’s data collection and C2 behaviors, and how stolen logs are monetized. It also describes a coordinated takedown on June 24, 2026, by Microsoft DCU and partners that disrupted hundreds of domains and C2 servers.
read more →

Windows 11 KB5095093 preview adds Point-in-Time

🛈 Microsoft released optional preview update KB5095093 for Windows 11 24H2 and 25H2, installing build 26100.8737 and introducing new features and bug fixes. The update offers a new Point-in-Time restore capability that captures VSS-based restore points for up to 72 hours and simplifies rollback of the OS, apps, and files. It also fixes a Recycle Bin filename confirmation bug and brings improvements across Secure Boot, Netlogon, File Explorer, Bluetooth, Widgets, accessibility, and networking.
read more →

Agentic cloud operations: insight to governed action

🧭 Agentic cloud operations use AI-powered agents to turn continuous observability into governed, auditable actions across the cloud lifecycle. Microsoft describes how Azure Copilot’s observability agent—now generally available—analyzes telemetry, traces dependencies, and surfaces grouped signals and contextual recommendations to speed incident resolution and reduce noise. Built-in governance and policy guardrails ensure actions respect controls and remain human-reviewed, while cost and usage intelligence integrate into developer tools to enable continuous optimization.
read more →

Defending AI Memory: Microsoft’s Multi‑Layer Strategy

🔒 Microsoft outlines a defense-in-depth approach to protect AI memory across storage, retrieval, model interaction, and user control. The post explains how memory transforms AI from stateless tool to learning collaborator, increasing attack surface and enabling staged attacks that persist beyond initial prompts. It summarizes protections in M365 Copilot including prompt-injection classifiers, Task Adherence checks, tenant policy controls, unified compliance, and audit logging integrated with Defender and Sentinel.
read more →

Microsoft confirms Windows 11 version 26H2 release

📰 Microsoft confirmed Windows 11 version 26H2 as the next feature update and has begun testing with Windows Insiders in the Dev Channel. The company says devices running Windows 11 24H2 and 25H2 can upgrade via a small 174 KB enablement package, while systems on 23H2 or older will need the full 6.5 GB update. Microsoft also published a whitepaper explaining the shared servicing model for these releases.
read more →

Microsoft fixes AutoGen Studio flaw enabling code execution

🛡️ Microsoft patched a vulnerability chain named AutoJack in AutoGen Studio that could allow a visiting webpage to coerce a developer’s AI agent into executing arbitrary commands on the host. AutoGen Studio is the graphical interface for Microsoft’s open-source AutoGen framework for multi-agent AI systems; the flaw was fixed during development and never shipped in a PyPI release. The issue affected developers who built from the main GitHub branch in a limited window and allowed attacker-supplied commands to be launched with the developer’s account privileges. Microsoft urges running AutoGen Studio only as a developer prototype in isolated, low-privilege environments and avoiding exposure to untrusted content.
read more →

One intrusion, two attackers: uncovering parallel threats

🔍 Microsoft DART describes a complex multi-stage intrusion where two unrelated threat actors operated simultaneously, blending ransomware tactics with stealthy reconnaissance and persistence. Investigators observed exploitation attempts against on-premises SharePoint, use of legitimate tools like Velociraptor, cloud tunneling, credential misuse, and DLL sideloading to maintain access and evade detection. Coordinated telemetry correlation and threat intelligence enabled containment and targeted remediation guidance.
read more →

Windows update breaks some Office OLE automations

🛠️ Microsoft’s June update has caused Office apps like Word and Excel to fail when launched via third-party software that relies on OLE automation. Affected integrations include CCH Engagement, Workpaper Manager, Zotero and dental systems such as Dentrix and Softdent, with users reporting files won’t open and no clear error is shown. Microsoft acknowledged the issue and is working on a fix, and also noted a separate cosmetic Recycle Bin filename display problem stemming from the same update.
read more →

Microsoft confirms Recycle Bin filename display bug

🛠️ Microsoft acknowledged a bug that causes the Recycle Bin confirmation dialog to show internal filenames (for example, $Rxxxxx.ext) instead of the original filename when permanently deleting a single item. The Recycle Bin view and restore operations continue to use the original filename. The issue affects all supported client and server Windows releases after installing the June 2026 security updates, and a fix is planned for a future update. Businesses can request a temporary workaround via Microsoft's Business Support.
read more →

Forrester TEI: 124% ROI from Microsoft Security

🔒 Microsoft commissioned Forrester Consulting to evaluate the economic impact of consolidating security with its AI-first, end-to-end platform. Based on interviews and a survey of customers, Forrester modeled a composite 10,000-employee B2B organization and projected $30M in benefits against $13.4M in costs over three years, yielding a 124% ROI and $16.6M NPV. The study highlights faster decisions, reduced friction, and improved defender productivity as key operational gains.
read more →

Microsoft fixes Windows Server 2016 update failures

🔧 Microsoft resolved a known issue that caused the June 2026 security update (KB5094122) to fail on Windows Server 2016 systems that were missing the prior month's KB5087537 update. Administrators had reported 0x80070002 or FILE_NOT_FOUND errors during installation. Microsoft confirmed the installation issue is fixed and affected devices should no longer experience failures deploying the June 2026 update. This follows several recent fixes for update- and boot-related problems across Windows releases.
read more →

Advancing Enterprise Security with AI-Driven Scanning

🛡️ Microsoft Security describes codename MDASH, a multi-model agentic scanning system built to discover, validate, and help remediate software vulnerabilities at enterprise scale. The system orchestrates specialized AI agents in a structured pipeline and integrates findings into Microsoft Defender, GitHub, and Azure DevOps workflows so issues become actionable engineering work. Early use across Windows, Azure, and identity teams uncovered numerous high-severity vulnerabilities before exploitation and helped raise CyberGym benchmark performance to 96.5%. The post reviews deployment lessons, failure modes, and planned improvements like fuzzing integration and broader artifact support.
read more →

Microsoft named Leader in Forrester XDR Wave 2026

🛡️ Microsoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026, earning the top Strategy and Vision scores. The report highlights Microsoft Defender and Microsoft Threat Intelligence for high marks across identity detection, cloud detection, SIEM replacement, threat hunting, and more. Microsoft emphasizes an XDR foundation that unifies signals across identities, endpoints, email, SaaS, and cloud workloads to enable coordinated, AI-assisted attack disruption and faster SOC operations.
read more →

Microsoft Confirms RoguePlanet Defender Zero-Day

🛡️ Microsoft disclosed it is preparing a patch for a Defender zero-day tracked as RoguePlanet, now identified as CVE-2026-50656 with a CVSS score of 7.8. The company classifies the issue as a privilege escalation in the Microsoft Malware Protection Engine and says it is working on a quality security update. The exploit was publicly released by researcher Chaotic Eclipse (aka Nightmare-Eclipse), who described it as a race condition that can yield SYSTEM-level shells and may work irrespective of real-time protection settings.
read more →

AI-Driven Identity Security: Microsoft Entra Updates

🔒 AI is accelerating cyberattacks, increasing speed and scale across the attack chain while identity remains a primary entry point. Microsoft highlights integrated visibility and response through Microsoft Entra and Microsoft Defender, including a unified identity risk score and an updated Entra ID Protection experience. New features aim to reduce fragmentation, enable least-privilege response roles, and automate policy optimization to help teams prevent, detect, and respond faster.
read more →

Microsoft confirms Office launch issue after June updates

🛠️ Microsoft is investigating reports that certain third-party applications may be unable to launch Word, Excel, PowerPoint, Access, and other Office apps or open documents after installing Windows updates released on or after June 9, 2026. The problem affects apps that use OLE automation, sometimes causing Office apps or documents to fail to open without an error. Microsoft advises opening Office files directly or contacting Microsoft Support for Business for enterprise workarounds while a fix is developed.
read more →

Microsoft developing patch for Defender RoguePlanet zero-day

🔒 Microsoft is investigating and preparing a security update for a Microsoft Defender elevation-of-privilege vulnerability publicly dubbed RoguePlanet. The flaw, now tracked as CVE-2026-50656, was disclosed with a proof-of-concept last week and reportedly allows spawning SYSTEM-level command prompts via a Defender race condition on fully patched Windows 10 and 11 devices. Microsoft confirmed it is working on a high-quality security update and will publish details in the CVE entry when available.
read more →

Microsoft Claims Defender May Replace Other Email Tools

📧 Microsoft’s benchmarking suggests Defender for Office 365 catches most malicious and spam email pre-delivery and removes nearly all threats that reach inboxes, with integrated partners adding negligible improvement. Experts caution against interpreting raw catch rates as proof that one-vendor stacks suffice, noting that small percentages can still represent high-impact incidents and that diverse tools and detection methods remain valuable.
read more →

GhostTree attack uses NTFS junctions to hide malware

🛡️ Attackers abuse NTFS junctions to create recursive directory loops that generate effectively infinite file paths, causing recursive scans and EDR products to hang. With only write access, an attacker can create junctions that point back to parent folders, producing GhostBranch or the more expansive GhostTree structures. These loops multiply possible paths exponentially, preventing file scanners from reaching malicious files and enabling evasion. Microsoft was notified and later patched the issue.
read more →