Skip to main content
← CVE Tracker

Vendor

Microsoft

266 articles

Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched
CRITICAL
Vulnerabilities

Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched

Analysis of Microsoft's April 2024 Patch Tuesday featuring 147 CVEs, including critical zero-days CVE-2024-26234 and CVE-2024-29988. Mitigation guide for SOCs.

Runtime Rebel Intel
3 min read · Jul 15, 2026
TH
MEDIUM
Threat Intel

Windows 11 Compatibility Hold for Dell Devices: Mitigation Guide

Microsoft blocks October 2024 Windows 11 updates for specific Dell hardware due to kernel-level conflicts causing spontaneous shutdowns and performance loss.

Runtime Rebel Intel
3 min read · Jul 15, 2026
VU
HIGH
Vulnerabilities

Microsoft Patch Tuesday: Addressing 570 Security Flaws

Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.

Runtime Rebel Intel
4 min read · Jul 15, 2026
VU
CRITICAL
Vulnerabilities

Microsoft Zero-Days: Active Directory & SharePoint Exploited

Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.

Runtime Rebel Intel
4 min read · Jul 15, 2026
Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now
CRITICAL
Vulnerabilities

Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now

Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.

Runtime Rebel Intel
4 min read · Jul 14, 2026
ModHeader Extension Pulled Over Dormant Browsing Data Collector
MEDIUM
Supply Chain

ModHeader Extension Pulled Over Dormant Browsing Data Collector

ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.

Runtime Rebel Intel
4 min read · Jul 13, 2026
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
MEDIUM
Threat Intel

Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks

Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.

Runtime Rebel Intel
3 min read · Jul 13, 2026
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
HIGH
Threat Intel

Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits

A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.

Runtime Rebel Intel
4 min read · Jul 13, 2026
Analyzing Microsoft BitLocker Security Wrapper Vulnerabilities
HIGH
Vulnerabilities

Analyzing Microsoft BitLocker Security Wrapper Vulnerabilities

New security vulnerabilities identified in a Microsoft BitLocker security wrapper pose a risk to organizations and potentially ATMs, potentially leading to compromise.

Runtime Rebel Intel
5 min read · Jul 10, 2026
Windows Defender RoguePlanet Zero-Day Threat: Patch Now
HIGH
Vulnerabilities

Windows Defender RoguePlanet Zero-Day Threat: Patch Now

Microsoft addresses the 'RoguePlanet' Windows Defender zero-day, with a PoC released by researcher Nightmare-Eclipse. Patching is critical.

Runtime Rebel Intel
4 min read · Jul 9, 2026
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
HIGH
Malware

GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware

Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.

Runtime Rebel Intel
5 min read · Jul 9, 2026
TH
HIGH
Threat Intel

Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise

Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.

Runtime Rebel Intel
4 min read · Jul 9, 2026
GodDamn Ransomware Leverages Signed Driver to Disable EDR
HIGH
Threat Intel

GodDamn Ransomware Leverages Signed Driver to Disable EDR

Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.

Runtime Rebel Intel
4 min read · Jul 9, 2026
VU
HIGH
Vulnerabilities

CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now

Microsoft patches 'RoguePlanet' vulnerability, CVE-2026-50656, in Defender's Malware Protection Engine, enabling privilege escalation. Update immediately.

Runtime Rebel Intel
5 min read · Jul 9, 2026
TH
INFO
Threat Intel

OWA Light Retirement in Exchange Server: Planning for the Change

Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…

Runtime Rebel Intel
4 min read · Jul 9, 2026
VU
CRITICAL
Vulnerabilities

Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide

Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.

Runtime Rebel Intel
4 min read · Jul 9, 2026
ID
HIGH
Identity & Access

Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk

A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.

Runtime Rebel Intel
5 min read · Jul 8, 2026
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
HIGH
Threat Intel

EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption

Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.

Runtime Rebel Intel
3 min read · Jul 8, 2026
CL
INFO
Cloud Security

Windows 11 26H2 Default Backup for Entra-Joined Systems

Microsoft will enable Windows settings backup by default for Entra-joined organizational systems after Windows 11 26H2 upgrade, impacting IT management and compliance.

Runtime Rebel Intel
4 min read · Jul 7, 2026
CL
INFO
Cloud Security

Microsoft Introduces Windows 11 Cloud Rebuild Recovery Feature

Microsoft is testing the new Cloud Rebuild recovery feature for Windows 11 Insider Preview, offering a streamlined, cloud-based OS reinstallation option.

Runtime Rebel Intel
5 min read · Jul 7, 2026
TH
HIGH
Threat Intel

EtherRAT Malware via Microsoft Teams IT Support Impersonation

Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.

Runtime Rebel Intel
5 min read · Jul 6, 2026
TH
MEDIUM
Threat Intel

ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit

ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.

Runtime Rebel Intel
5 min read · Jul 3, 2026
CL
INFO
Cloud Security

Microsoft Teams: New Controls for AI Bot Meeting Access

Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.

Runtime Rebel Intel
4 min read · Jul 2, 2026
SU
INFO
Supply Chain

Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency

Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.

Runtime Rebel Intel
4 min read · Jul 1, 2026