Advertisement
CVE-2026-85880: Windows ALPC Heap Overflow Exploited
CISA confirms active exploitation of CVE-2026-85880, a heap-based buffer overflow in Microsoft Windows ALPC leading to local privilege escalation.
Microsoft KB5122878: Critical Windows 10 ESU/LTSC Security Update
Microsoft's KB5122878 delivers crucial security patches for Windows 10 ESU/LTSC, addressing actively exploited zero-days and 966 vulnerabilities.
BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs
BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.
Microsoft 365 Vishing Leads to Executive Data Theft, Extortion
A widespread threat cluster, PREY-0058, targets Microsoft 365 executives with vishing, AitM token theft, and data extortion.
Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends
Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.
Silver Fox Malware Campaign Impersonates Software Vendors
An active Silver Fox malware campaign uses fake software download sites to disable Windows Update and weaken Microsoft Defender defenses.
Microsoft Defender Blocks Legitimate Google Search Links
Microsoft Defender for Office 365's Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.
CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack
Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
Mabna Institute Espionage, BTR.sys Kernel Bypass, & Malware
Runtime Rebel details state-sponsored espionage by Mabna Institute, a kernel-level bypass using Microsoft Defender's BTR.sys, and new malware campaigns.
Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated
Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.
Weaponizing Defender's BTR.sys to Disable Security Software
Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.
SynkLoader Malware Steals Credentials in Microsoft Teams Phishing
New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.
Entra Log Analysis: Detecting Password Spray Attacks with PowerShell
Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.
Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph
A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.
Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws
Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.
CoSnitch Attack: Tricking Microsoft Copilot Reveal Architecture
Researchers reveal the CoSnitch technique that tricks Microsoft Copilot into exposing internal architecture, highlighting AI meta‑hacking risks.
CVE-2026-33824: Microsoft IKE Double Free RCE Exploit
CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.
CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal
Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.
Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics
Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.
SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now
An AI-assisted exploit chain, leveraging CVE-2026-55040 and CVE-2026-63520, enables unauthenticated RCE on Microsoft SharePoint Server. Immediate patching is critical.
ShieldBreak: Windows Zero-Day EoP via Microsoft Defender
Security researcher Nightmare Eclipse released 'ShieldBreak,' a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.
CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC
Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.
CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited
Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows' afd.sys component.