CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild
Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability
Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.
Microsoft Introduces Remote Rollback for Faulty Windows Drivers
Microsoft expands its Known Issue Rollback capability to Windows drivers, allowing remote remediation of faulty updates that cause boot loops or crashes.
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.
KongTuke Exploits Microsoft Teams for Rapid Corporate Breaches
Initial access broker KongTuke leverages Microsoft Teams to deploy DarkGate malware, achieving network persistence in under five minutes via social engineering.
Outlook Junk Folder Bypass: How Attackers Hide Malicious URLs
Discover how attackers bypass Microsoft Outlook's Junk folder link preview protection using HTML manipulation to hide malicious phishing URLs from users.
Microsoft and Palo Alto Networks Use AI to Identify Dozens of Vulnerabilities
Microsoft and Palo Alto Networks leverage AI-powered tools MDASH and Mythos to identify dozens of critical software vulnerabilities before exploitation.
FamousSparrow Exploits Microsoft Exchange in Azerbaijani Energy Campaign
Bitdefender reveals a multi-wave intrusion by FamousSparrow targeting an Azerbaijani oil and gas firm via repeated Microsoft Exchange exploitation.
Microsoft MDASH AI Discovers 16 Windows Vulnerabilities
Microsoft reveals MDASH, a new AI-driven agentic scanning harness that discovered 16 vulnerabilities in Windows, now fixed in recent Patch Tuesday updates.
May 2026 Patch Tuesday: 30 Critical CVEs Require Immediate Attention
Runtime Rebel analyzes May 2026 Patch Tuesday, detailing 130 CVEs, including 30 critical flaws impacting Microsoft products.
Microsoft Patch Tuesday: 9 Critical Flaws Among 137 Total Fixes
Microsoft's latest Patch Tuesday addresses 137 vulnerabilities, including 9 critical flaws. While no zero-days were reported, timely patching is essential.
Microsoft May 2026 Patch Tuesday: 274 Vulnerabilities Addressed
Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities in Windows and 137 Chromium-related issues affecting Microsoft Edge.
Microsoft's 137 Patches: Critical Flaws in Azure, Windows, Dynamics
Microsoft's latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.
Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.
MuddyWater Exploits Microsoft Teams via Chaos Ransomware Decoy
Iranian APT MuddyWater utilizes Microsoft Teams social engineering and Chaos ransomware decoys to mask state-sponsored espionage operations.
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.
Managed Threat Hunting: CrowdStrike OverWatch for Microsoft Defender
Runtime Rebel analyzes CrowdStrike's new Falcon OverWatch for Defender, detailing how it enhances threat hunting for Microsoft Defender users and boosts defenses.
Microsoft Edge Password Storage: Risk of Credential Dumping
Microsoft Edge stores sensitive user passwords in process memory. A PoC exploit demonstrates how attackers with admin privileges can dump credentials, posing significant…
AitM Phishing Attacks Target US Organizations with Conduct Reports
Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.
Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.
Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide
Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.
Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users
Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.
CVE-2024-1086: Copy Fail Linux Privilege Escalation Under Exploitation
CISA adds CVE-2024-1086 (Copy Fail) to its KEV catalog after Microsoft observes exploitation of this Linux Netfilter privilege escalation vulnerability.
Microsoft Defender DigiCert False Positive: Trojan:Win32/Cerdigent.A!dha
Microsoft Defender is incorrectly identifying DigiCert root certificates as the Cerdigent trojan, causing certificate removal and enterprise disruptions.