Skip to main content
← CVE Tracker

Vendor

Microsoft

266 articles

TH
HIGH
Threat Intel

FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts

The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.

Runtime Rebel Intel
3 min read · May 25, 2026
Webworm Group Exploits Discord and MS Graph to Target EU Governments
HIGH
Threat Intel

Webworm Group Exploits Discord and MS Graph to Target EU Governments

China-linked threat actor Webworm utilizes Discord and Microsoft Graph API for C2 infrastructure in a campaign targeting European government organizations.

Runtime Rebel Intel
4 min read · May 22, 2026
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
HIGH
Vulnerabilities

Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited

Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.

Runtime Rebel Intel
3 min read · May 21, 2026
VU
HIGH
Vulnerabilities

CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited

CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.

Runtime Rebel Intel
3 min read · May 21, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus

Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.

Runtime Rebel Intel
4 min read · May 21, 2026
VU
HIGH
Vulnerabilities

YellowKey BitLocker Bypass: Microsoft Mitigates Data Access

Microsoft addresses the 'YellowKey' BitLocker bypass, preventing unauthorized data access via the FsTx Auto Recovery Utility in WinRE. Understand the threat.

Runtime Rebel Intel
5 min read · May 20, 2026
Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation
INFO
Threat Intel

Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation

Microsoft open-sources RAMPART and Clarity to provide developers with frameworks for red teaming and observing autonomous AI agents against prompt injection.

Runtime Rebel Intel
4 min read · May 20, 2026
VU
HIGH
Vulnerabilities

YellowKey Zero-Day: Mitigating BitLocker Encryption Bypasses in Windows

Microsoft releases mitigation guidance for the YellowKey zero-day, a Windows BitLocker vulnerability allowing unauthorized access to encrypted data volumes.

Runtime Rebel Intel
3 min read · May 20, 2026
TH
HIGH
Threat Intel

Microsoft Disrupts MSaaS Operation Abusing Artifact Signing Service

Microsoft shuts down a malware-signing-as-a-service provider that leveraged fraudulent certificates to bypass security controls for ransomware groups.

Runtime Rebel Intel
3 min read · May 20, 2026
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
HIGH
Malware

SHub Reaper Stealer Backdoors macOS via Spoofed Apps

SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.

Runtime Rebel Intel
5 min read · May 19, 2026
TH
MEDIUM
Threat Intel

Microsoft Disrupts Fox Tempest Malware Signing Service

Microsoft dismantled the Fox Tempest (Storm-1152) malware signing service, which issued over 10,000 fraudulent certificates to mask ransomware and other malware.

Runtime Rebel Intel
5 min read · May 19, 2026
TH
INFO
Threat Intel

Microsoft's 2026 Plan: Enhancing Windows 11 Driver Quality and Security

Microsoft outlines plans for 2026 to significantly enhance Windows 11 driver quality, aiming to bolster system stability and security from the core up.

Runtime Rebel Intel
4 min read · May 19, 2026
TH
HIGH
Threat Intel

Windows Update Failures in Restricted Networks via January 2025 Patch

Microsoft confirms January 2025 non-security updates cause Windows Update failures in restricted networks. Learn how to resolve metadata service connection errors.

Runtime Rebel Intel
3 min read · May 19, 2026
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
HIGH
Threat Intel

EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow

The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.

Runtime Rebel Intel
4 min read · May 19, 2026
CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack

Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.

Runtime Rebel Intel
5 min read · May 19, 2026
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
CRITICAL
Threat Intel

Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use

Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.

Runtime Rebel Intel
3 min read · May 18, 2026
TH
INFO
Threat Intel

Windows 11 Resizable Taskbar and Start Menu Preview Analysis

Microsoft initiates testing for resizable taskbar and Start menu features in Windows 11 Insider builds, addressing long-standing UI customization requests.

Runtime Rebel Intel
3 min read · May 18, 2026
VU
MEDIUM
Vulnerabilities

Windows 11 KB5089549 Security Update Installation Failure Analysis

Microsoft confirms Windows 11 KB5089549 security update fails with error 0x800f0922. Learn how to troubleshoot and resolve these installation issues.

Runtime Rebel Intel
4 min read · May 18, 2026
TH
MEDIUM
Threat Intel

Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow

Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.

Runtime Rebel Intel
3 min read · May 17, 2026
CL
MEDIUM
Cloud Security

Azure Backup for AKS Vulnerability: Risks of Silent Patches

A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.

Runtime Rebel Intel
3 min read · May 17, 2026
TH
HIGH
Threat Intel

BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion

Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.

Runtime Rebel Intel
6 min read · May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation

CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.

Runtime Rebel Intel
4 min read · May 15, 2026
VU
HIGH
Vulnerabilities

Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits

Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.

Runtime Rebel Intel
4 min read · May 15, 2026
TH
INFO
Threat Intel

Microsoft Edge: Hardening Against Cleartext Password Exposure

Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.

Runtime Rebel Intel
4 min read · May 15, 2026