ConsentFix v3: How Attackers Automate Azure OAuth Abuse
Attackers use ConsentFix v3 to automate illicit consent grants in Microsoft Azure, enabling persistent access to Entra ID data without user passwords.
Windows 11 Modern Run Dialog: Technical Overview and Security Analysis
Microsoft updates the Windows 11 Run dialog in Insider Preview Build 27793 with WinUI 3 components, Dark Mode, and improved performance for OS interactions.
Windows 11 24H2 Remote Desktop Security Warning Bug Patched
Microsoft resolves a Windows 11 24H2 bug where Remote Desktop (.rdp) security warnings failed to display correctly after the October 2024 updates.
KB5083631 Update: Windows 11 Batch File and Startup Performance
Microsoft releases KB5083631 for Windows 11, introducing batch file security enhancements, Xbox Game Bar updates, and optimizations for startup applications.
Managed Windows 11 Bloatware Removal: New IT Admin Policy Controls
Microsoft updates Windows 11 policy allowing IT admins to selectively uninstall pre-installed Store apps, reducing the attack surface in managed environments.
Microsoft Teams Free Backend Change Disrupts Chat and Calling
Microsoft confirms a backend configuration change has broken core functionality for Microsoft Teams Free users, impacting global business communication.
Microsoft RDP Security Warning Display Bug — Mitigation Guide
Microsoft confirms security warnings for Remote Desktop (.rdp) files may display incorrectly on Windows 10 and 11, potentially obscuring risk information.
Microsoft Outlook iOS Authentication Issues: Remediation and Risks
Microsoft resolves global Outlook.com outage but requires iOS Mail app users to re-authenticate. Learn how to secure accounts and mitigate phishing risks.
CVE-2026-32202: Active Exploitation of Windows Shell Spoofing Bug
Microsoft confirms CVE-2026-32202, a Windows Shell spoofing flaw, is under active exploitation. Read our analysis and mitigation guide for enterprise security.
Microsoft Entra ID Flaw: Agent ID Administrator Role Escalation
Microsoft patches a critical logic flaw in the Entra ID Agent ID Administrator role that allowed attackers to take over service principals and escalate privileges.
UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse
Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom 'Snow' malware and AWS S3 cloud abuse in multi-pronged attacks.
Microsoft Outlook.com Sign-In Failures: Analysis of Ongoing Outage
Microsoft confirms an Outlook.com outage causing intermittent sign-in failures and mailbox access issues. Learn about the impact on enterprise productivity.
Microsoft Revamps Windows Insider Program for Windows 11 Testing
Microsoft's Windows Insider Program overhaul introduces new Canary and Dev channels, changing how security teams test Windows 11 reliability and performance.
UNC6692 Targets Microsoft Teams to Deploy Snow Malware
UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.
Microsoft Enterprise Copilot: New Uninstall Policy for Admins
Microsoft introduces a new policy setting allowing IT administrators to uninstall Copilot from enterprise devices, enhancing management and control over AI features.
UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite
UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.
UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams
UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…
CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now
CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.
CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis
Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.
Critical RCE Threats: Confluence OGNL & Exchange Server Patching
Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.
CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis
CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.
Microsoft Universal Print Issues Traced to Graph API Code Change
Microsoft identifies a recent Graph API code change as the root cause for ongoing Universal Print sharing issues affecting user ability to create printer shares.
Microsoft Teams Efficiency Mode: Optimizing Resource Usage for PCs
Microsoft introduces Efficiency Mode for Teams to reduce CPU and memory consumption on resource-constrained devices, improving overall system responsiveness.