Skip to main content
← CVE Tracker

Vendor

Microsoft

266 articles

CL
HIGH
Cloud Security

ConsentFix v3: How Attackers Automate Azure OAuth Abuse

Attackers use ConsentFix v3 to automate illicit consent grants in Microsoft Azure, enabling persistent access to Entra ID data without user passwords.

Runtime Rebel Intel
4 min read · May 2, 2026
TH
INFO
Threat Intel

Windows 11 Modern Run Dialog: Technical Overview and Security Analysis

Microsoft updates the Windows 11 Run dialog in Insider Preview Build 27793 with WinUI 3 components, Dark Mode, and improved performance for OS interactions.

Runtime Rebel Intel
3 min read · May 2, 2026
VU
LOW
Vulnerabilities

Windows 11 24H2 Remote Desktop Security Warning Bug Patched

Microsoft resolves a Windows 11 24H2 bug where Remote Desktop (.rdp) security warnings failed to display correctly after the October 2024 updates.

Runtime Rebel Intel
3 min read · May 1, 2026
VU
LOW
Vulnerabilities

KB5083631 Update: Windows 11 Batch File and Startup Performance

Microsoft releases KB5083631 for Windows 11, introducing batch file security enhancements, Xbox Game Bar updates, and optimizations for startup applications.

Runtime Rebel Intel
3 min read · May 1, 2026
ID
INFO
Identity & Access

Managed Windows 11 Bloatware Removal: New IT Admin Policy Controls

Microsoft updates Windows 11 policy allowing IT admins to selectively uninstall pre-installed Store apps, reducing the attack surface in managed environments.

Runtime Rebel Intel
4 min read · May 1, 2026
CL
LOW
Cloud Security

Microsoft Teams Free Backend Change Disrupts Chat and Calling

Microsoft confirms a backend configuration change has broken core functionality for Microsoft Teams Free users, impacting global business communication.

Runtime Rebel Intel
3 min read · Apr 29, 2026
VU
MEDIUM
Vulnerabilities

Microsoft RDP Security Warning Display Bug — Mitigation Guide

Microsoft confirms security warnings for Remote Desktop (.rdp) files may display incorrectly on Windows 10 and 11, potentially obscuring risk information.

Runtime Rebel Intel
4 min read · Apr 28, 2026
CL
LOW
Cloud Security

Microsoft Outlook iOS Authentication Issues: Remediation and Risks

Microsoft resolves global Outlook.com outage but requires iOS Mail app users to re-authenticate. Learn how to secure accounts and mitigate phishing risks.

Runtime Rebel Intel
4 min read · Apr 28, 2026
CVE-2026-32202: Active Exploitation of Windows Shell Spoofing Bug
HIGH
Vulnerabilities

CVE-2026-32202: Active Exploitation of Windows Shell Spoofing Bug

Microsoft confirms CVE-2026-32202, a Windows Shell spoofing flaw, is under active exploitation. Read our analysis and mitigation guide for enterprise security.

Runtime Rebel Intel
4 min read · Apr 28, 2026
Microsoft Entra ID Flaw: Agent ID Administrator Role Escalation
HIGH
Identity & Access

Microsoft Entra ID Flaw: Agent ID Administrator Role Escalation

Microsoft patches a critical logic flaw in the Entra ID Agent ID Administrator role that allowed attackers to take over service principals and escalate privileges.

Runtime Rebel Intel
4 min read · Apr 28, 2026
UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse
HIGH
Cloud Security

UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse

Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom 'Snow' malware and AWS S3 cloud abuse in multi-pronged attacks.

Runtime Rebel Intel
5 min read · Apr 27, 2026
ID
MEDIUM
Identity & Access

Microsoft Outlook.com Sign-In Failures: Analysis of Ongoing Outage

Microsoft confirms an Outlook.com outage causing intermittent sign-in failures and mailbox access issues. Learn about the impact on enterprise productivity.

Runtime Rebel Intel
4 min read · Apr 27, 2026
TH
INFO
Threat Intel

Microsoft Revamps Windows Insider Program for Windows 11 Testing

Microsoft's Windows Insider Program overhaul introduces new Canary and Dev channels, changing how security teams test Windows 11 reliability and performance.

Runtime Rebel Intel
3 min read · Apr 25, 2026
TH
HIGH
Threat Intel

UNC6692 Targets Microsoft Teams to Deploy Snow Malware

UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.

Runtime Rebel Intel
3 min read · Apr 25, 2026
CL
INFO
Cloud Security

Microsoft Enterprise Copilot: New Uninstall Policy for Admins

Microsoft introduces a new policy setting allowing IT administrators to uninstall Copilot from enterprise devices, enhancing management and control over AI features.

Runtime Rebel Intel
4 min read · Apr 24, 2026
TH
HIGH
Threat Intel

UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite

UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.

Runtime Rebel Intel
4 min read · Apr 24, 2026
UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams
HIGH
Threat Intel

UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams

UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.

Runtime Rebel Intel
4 min read · Apr 23, 2026
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
HIGH
Threat Intel

Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage

A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…

Runtime Rebel Intel
4 min read · Apr 23, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now

CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis

Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.

Runtime Rebel Intel
3 min read · Apr 23, 2026
VU
CRITICAL
Vulnerabilities

Critical RCE Threats: Confluence OGNL & Exchange Server Patching

Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.

Runtime Rebel Intel
5 min read · Apr 23, 2026
VU
HIGH
Vulnerabilities

CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis

CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.

Runtime Rebel Intel
4 min read · Apr 23, 2026
CL
INFO
Cloud Security

Microsoft Universal Print Issues Traced to Graph API Code Change

Microsoft identifies a recent Graph API code change as the root cause for ongoing Universal Print sharing issues affecting user ability to create printer shares.

Runtime Rebel Intel
4 min read · Apr 22, 2026
TH
INFO
Threat Intel

Microsoft Teams Efficiency Mode: Optimizing Resource Usage for PCs

Microsoft introduces Efficiency Mode for Teams to reduce CPU and memory consumption on resource-constrained devices, improving overall system responsiveness.

Runtime Rebel Intel
4 min read · Apr 22, 2026