Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched
Analysis of Microsoft's April 2024 Patch Tuesday featuring 147 CVEs, including critical zero-days CVE-2024-26234 and CVE-2024-29988. Mitigation guide for SOCs.
Windows 11 Compatibility Hold for Dell Devices: Mitigation Guide
Microsoft blocks October 2024 Windows 11 updates for specific Dell hardware due to kernel-level conflicts causing spontaneous shutdowns and performance loss.
Microsoft Patch Tuesday: Addressing 570 Security Flaws
Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.
Microsoft Zero-Days: Active Directory & SharePoint Exploited
Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.
Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now
Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.
ModHeader Extension Pulled Over Dormant Browsing Data Collector
ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.
Analyzing Microsoft BitLocker Security Wrapper Vulnerabilities
New security vulnerabilities identified in a Microsoft BitLocker security wrapper pose a risk to organizations and potentially ATMs, potentially leading to compromise.
Windows Defender RoguePlanet Zero-Day Threat: Patch Now
Microsoft addresses the 'RoguePlanet' Windows Defender zero-day, with a PoC released by researcher Nightmare-Eclipse. Patching is critical.
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.
Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise
Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.
GodDamn Ransomware Leverages Signed Driver to Disable EDR
Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.
CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now
Microsoft patches 'RoguePlanet' vulnerability, CVE-2026-50656, in Defender's Malware Protection Engine, enabling privilege escalation. Update immediately.
OWA Light Retirement in Exchange Server: Planning for the Change
Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…
Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide
Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.
Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk
A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.
Windows 11 26H2 Default Backup for Entra-Joined Systems
Microsoft will enable Windows settings backup by default for Entra-joined organizational systems after Windows 11 26H2 upgrade, impacting IT management and compliance.
Microsoft Introduces Windows 11 Cloud Rebuild Recovery Feature
Microsoft is testing the new Cloud Rebuild recovery feature for Windows 11 Insider Preview, offering a streamlined, cloud-based OS reinstallation option.
EtherRAT Malware via Microsoft Teams IT Support Impersonation
Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.
ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit
ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.
Microsoft Teams: New Controls for AI Bot Meeting Access
Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.
Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency
Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.