Skip to main content
← CVE Tracker

Vendor

Microsoft

285 articles

Advertisement

CRITICAL
Vulnerabilities

Microsoft Patch Tuesday March 2026: 8 Critical Vulnerabilities Addressed

Microsoft's March 2026 Patch Tuesday addresses 93 vulnerabilities, including 8 critical issues across various products and 9 in Microsoft Edge (Chromium).

Runtime Rebel Intel
4 min read · Mar 10, 2026
HIGH
Vulnerabilities

Microsoft Patch Tuesday: 83 Vulnerabilities, Critical Flaw Addressed

Microsoft's latest Patch Tuesday addresses 83 vulnerabilities across its product line, including one critical flaw. Security teams must prioritize immediate patching.

Runtime Rebel Intel
4 min read · Mar 10, 2026
HIGH
Vulnerabilities

Windows 10 KB5078885 ESU Fixes Two Zero-Days — Patch Guidance

Microsoft releases Windows 10 KB5078885 Extended Security Update to address two zero-day vulnerabilities and a critical system shutdown bug for ESU subscribers.

Runtime Rebel Intel
3 min read · Mar 10, 2026
INFO
Identity & Access

Entra Passkeys: Phishing-Resistant Windows Sign-In Deployment

Microsoft introduces phishing-resistant passkey support for Entra ID on Windows, leveraging Windows Hello to secure the sign-in process against credential theft.

Runtime Rebel Intel
3 min read · Mar 10, 2026
INFO
Vulnerabilities

Microsoft Windows Hotpatching to be Enabled by Default in May 2026

Microsoft will enable hotpatching by default for Intune-managed Windows devices in May 2026, allowing security updates without reboots to reduce downtime.

Runtime Rebel Intel
3 min read · Mar 10, 2026
HIGH
Threat Intel

Microsoft Teams Phishing Deploys A0Backdoor via Quick Assist

Attackers are targeting healthcare and finance employees with Microsoft Teams phishing to deploy A0Backdoor using the native Windows Quick Assist tool.

Runtime Rebel Intel
4 min read · Mar 10, 2026
MEDIUM
Identity & Access

Microsoft Teams Third-Party Bot Tagging Enhances Meeting Security

Microsoft Teams updates meeting lobbies to identify third-party bots, helping administrators prevent unauthorized data collection and social engineering.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Threat Intel

AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups

Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.

Runtime Rebel Intel
4 min read · Mar 7, 2026
Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer
HIGH
Threat Intel

Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer

Microsoft identifies a new ClickFix campaign using Windows Terminal to deliver Lumma Stealer. Analysis of social engineering TTPs and mitigation steps included.

Runtime Rebel Intel
4 min read · Mar 6, 2026
HIGH
Malware

Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers

Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.

Runtime Rebel Intel
4 min read · Mar 6, 2026
HIGH
Vulnerabilities

Microsoft Outlook CVE-2025-21418: Mitigating NTLM Relay Attacks

Analysis of CVE-2025-21418 in Microsoft Outlook. Learn how attackers bypass security features to leak NTLM hashes and the steps needed for mitigation.

Runtime Rebel Intel
3 min read · Mar 5, 2026
Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps
HIGH
Identity & Access

Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps

Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.

Runtime Rebel Intel
3 min read · Mar 5, 2026
MEDIUM
Threat Intel

Sentencing in $24 Million Microsoft Licensing Fraud Scheme

A Florida woman has been sentenced to 22 months in prison for a multi-million dollar scheme involving stolen Microsoft Certificate of Authenticity labels.

Runtime Rebel Intel
3 min read · Mar 2, 2026
APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence
CRITICAL
Threat Intel

APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence

Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft's February 2026 security patch updates.

Runtime Rebel Intel
3 min read · Mar 2, 2026
INFO
Threat Intel

Windows 11 Hardens Batch File Execution to Counter Script Attacks

Microsoft tests security enhancements for batch and CMD files in Windows 11 Insider Build 27723 to mitigate Living-off-the-Land (LotL) script abuse.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware
MEDIUM
Threat Intel

Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware

Microsoft warns developers of a coordinated campaign using malicious Next.js repositories disguised as job assessments to deliver in-memory malware.

Runtime Rebel Intel
3 min read · Feb 26, 2026
HIGH
Supply Chain

Fake Next.js Job Interview Tests Backdoor Developers

Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.

Runtime Rebel Intel
5 min read · Feb 26, 2026
INFO
Threat Intel

Windows 11 KB5077241: Native Sysmon Integration and BitLocker Updates

Microsoft integrates native Sysmon and enhances BitLocker management in the Windows 11 KB5077241 optional update, providing advanced telemetry for defenders.

Runtime Rebel Intel
4 min read · Feb 25, 2026
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
CRITICAL
Vulnerabilities

January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws

Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.

Runtime Rebel Intel
5 min read · Feb 25, 2026
LOW
Vulnerabilities

Microsoft Investigating Mouse Pointer Bug in Classic Outlook

Microsoft confirms a bug in classic Outlook causing the mouse cursor to disappear during email composition. Discover the technical details and mitigation steps.

Runtime Rebel Intel
4 min read · Feb 24, 2026
CRITICAL
Vulnerabilities

Microsoft February 2026 Security Update: Analysis of Six Actively Exploited Zero-Days

Microsoft's latest security release addresses 50+ vulnerabilities, including six zero-day exploits targeting Windows kernel components and browser engines.

Runtime Rebel Intel
2 min read · Feb 23, 2026