CISA KEV Catalog Update: Microsoft Office RCE and SharePoint Exploited
CISA adds CVE-2009-0238 (Microsoft Office RCE) and CVE-2026-32201 (SharePoint Server input validation) to its Known Exploited Vulnerabilities Catalog.
CVE-2024-30044: SharePoint Server RCE Zero-Day Patched — Patch Now
Microsoft's May 2024 Patch Tuesday addresses 61 vulnerabilities including a critical SharePoint RCE zero-day and a Windows DWM elevation of privilege flaw.
Windows 10 KB5082200 ESU: Patching April 2026 Zero-Day Flaws
Microsoft addresses two critical zero-days in the Windows 10 KB5082200 Extended Security Update. Learn how to secure EOL systems against active exploitation.
Microsoft Windows Hardware Program Fast-Track Reinstatement Guide
Microsoft launches a fast-track process for developers to recover Windows Hardware Program accounts suspended during recent driver-signing security audits.
CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits
CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…
Storm-2755 Targets Canadian Employees in Payroll Pirate Campaigns
Microsoft warns of Storm-2755, a financially motivated threat actor hijacking employee accounts to redirect salary payments via sophisticated phishing.
CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets
Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.
VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins
Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.
Federal Evaluators Flag Microsoft Cloud Security Documentation
U.S. federal evaluators expressed a 'lack of confidence' in Microsoft's cloud security posture due to insufficient documentation, despite approval.
Microsoft Developer Account Suspensions Block OSS Security Patches
Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.
Windows 11 23H2 Start Menu Search Fix — Microsoft Implementation Guide
Microsoft has resolved a Windows 11 23H2 bug causing Start Menu search failures using a Known Issue Rollback. Discover how this fix impacts system stability.
Russian Hackers Exploit Routers to Steal Microsoft Office Tokens
Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…
APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins
Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.
Fix for Classic Outlook 0x80040115 Error Restores Email Delivery
Microsoft resolves a persistent bug in Classic Outlook causing 0x80040115 errors and email delivery failures for Outlook.com users. Learn how to fix it.
Iran-Linked Password-Spraying Targets 300+ Israeli Organizations
Iran-linked threat actors launched coordinated password-spraying attacks against Israeli and UAE Microsoft 365 environments in March 2026.
Axios npm Hijack Attempt: Detecting Social Engineering Tactics
North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.
Exchange Online Mailbox Access Issues Persist for Outlook Users
Microsoft Exchange Online users on Outlook mobile and macOS are experiencing intermittent mailbox access issues for weeks; investigation ongoing.
Windows 11 Version 24H2 Force Upgrade for Unmanaged PCs
Microsoft initiates forced upgrades to Windows 11 24H2 for unmanaged Home and Pro devices to maintain security support and critical update delivery.
Classic Outlook Bug Halts Outlook.com Email Delivery for Users
Microsoft is actively investigating a Classic Outlook bug preventing some users from sending emails via Outlook.com. This impacts email delivery and communication.
EvilTokens Fuels Microsoft Device Code Phishing & BEC
New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…
Windows 11 KB5086672 Emergency Update Fixes Installation Issues
Microsoft issues emergency update KB5086672 to resolve installation failures and boot loops caused by the KB5079391 non-security preview update.
Microsoft Fixes Outlook Classic Crashes Caused by Teams Add-in
Microsoft resolves persistent crashes in Outlook Classic triggered by the Teams Meeting Add-in. Technical details for IT administrators to verify the fix.