Advertisement
Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day
Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.
Swiss Government SharePoint Breach: 200 Accounts Compromised
Switzerland's federal IT office confirms a Microsoft SharePoint breach compromised approximately 200 accounts, leading to a swift remediation.
Microsoft & Apple Patch Critical RCEs and Auth Bypass Flaws
Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.
CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now
CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…
Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word
Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.
Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations
Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.
Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide
An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.
Windows 11 KB5101684 Preview Update Addresses 42 System Issues
Microsoft releases KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, fixing 42 bugs across Start menu, Task Manager, and Sandbox environments.
CVE-2024-49019: Certighost AD CS Privilege Escalation Explained
Analysis of CVE-2024-49019, the Certighost flaw in Microsoft AD CS. Learn how misconfigured certificate templates allow full Active Directory compromise.
Microsoft MAI-Cyber-1-Flash: Performance Analysis of Security LLM
Microsoft introduces MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, outperforming competitors in CyberGym benchmark testing.
Microsoft MDASH Update: MAI-Cyber-1-Flash Achieves 95.95% Accuracy
Microsoft announces MAI-Cyber-1-Flash for its MDASH harness, delivering 95.95% vulnerability remediation accuracy at half the previous operational cost.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.
Microsoft Fixes Exchange Online Erroneous Mailbox Quarantine Issue
Microsoft is mitigating a service disruption where Exchange Online mailboxes were incorrectly quarantined, causing delivery failures and access issues.
CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys
Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.
WSUS Sync Delays & Timeouts: Microsoft's Manual Fix Guidance
Microsoft provides manual steps to resolve persistent sync delays and timeouts impacting Windows Server Update Services (WSUS) deployments, affecting Windows Update…
HollowGraph Malware Uses Microsoft Graph for Stealthy C2
HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
KB5121767: Microsoft Fixes Windows 11 Dell PC Shutdown Bug
Microsoft issues emergency out-of-band update KB5121767 to resolve critical system shutdown issues affecting Dell PCs running the July 2026 Windows 11 update.
Microsoft Investigates WSUS Server Synchronization Timeout Errors
Microsoft confirms technical issues causing WSUS synchronization delays and timeouts. Learn how this affects enterprise patch management and security.
ACR Stealer Campaign Targets Microsoft Enterprise Credentials
Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.
Windows Server 2022 Mainstream Support Transition: Strategic Guide
Microsoft outlines the Windows Server 2022 transition to extended support in October 2026. Learn how this lifecycle shift impacts security updates and SOC planning.