FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts
The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.
Webworm Group Exploits Discord and MS Graph to Target EU Governments
China-linked threat actor Webworm utilizes Discord and Microsoft Graph API for C2 infrastructure in a campaign targeting European government organizations.
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.
CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited
CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.
CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus
Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.
YellowKey BitLocker Bypass: Microsoft Mitigates Data Access
Microsoft addresses the 'YellowKey' BitLocker bypass, preventing unauthorized data access via the FsTx Auto Recovery Utility in WinRE. Understand the threat.
Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation
Microsoft open-sources RAMPART and Clarity to provide developers with frameworks for red teaming and observing autonomous AI agents against prompt injection.
YellowKey Zero-Day: Mitigating BitLocker Encryption Bypasses in Windows
Microsoft releases mitigation guidance for the YellowKey zero-day, a Windows BitLocker vulnerability allowing unauthorized access to encrypted data volumes.
Microsoft Disrupts MSaaS Operation Abusing Artifact Signing Service
Microsoft shuts down a malware-signing-as-a-service provider that leveraged fraudulent certificates to bypass security controls for ransomware groups.
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.
Microsoft Disrupts Fox Tempest Malware Signing Service
Microsoft dismantled the Fox Tempest (Storm-1152) malware signing service, which issued over 10,000 fraudulent certificates to mask ransomware and other malware.
Microsoft's 2026 Plan: Enhancing Windows 11 Driver Quality and Security
Microsoft outlines plans for 2026 to significantly enhance Windows 11 driver quality, aiming to bolster system stability and security from the core up.
Windows Update Failures in Restricted Networks via January 2025 Patch
Microsoft confirms January 2025 non-security updates cause Windows Update failures in restricted networks. Learn how to resolve metadata service connection errors.
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.
CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.
Windows 11 Resizable Taskbar and Start Menu Preview Analysis
Microsoft initiates testing for resizable taskbar and Start menu features in Windows 11 Insider builds, addressing long-standing UI customization requests.
Windows 11 KB5089549 Security Update Installation Failure Analysis
Microsoft confirms Windows 11 KB5089549 security update fails with error 0x800f0922. Learn how to troubleshoot and resolve these installation issues.
Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow
Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.
Azure Backup for AKS Vulnerability: Risks of Silent Patches
A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.
CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation
CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.
Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits
Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.
Microsoft Edge: Hardening Against Cleartext Password Exposure
Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.