Tag

#Microsoft

27 published stories tagged with Microsoft.

highAPT / Nation-StateJul 29, 20264 min read

Laundry Bear exploits Exchange OWA zero-day to deploy persistent OWAReaper backdoor via email

The Russian state-sponsored group Laundry Bear (TA488) is using a "half-click" exploit against Microsoft Exchange Outlook Web Access (OWA) to deploy the OWAReaper backdoor.

highAPT / Nation-StateJul 29, 20262 min read

Russian Hackers Maintain Mailbox Access After Credential Rotation via Microsoft OWA Flaw

馃毃 Russian-linked actors are targeting Microsoft Exchange Online environments through vulnerabilities in Outlook Web Access (OWA).

criticalExploited VulnerabilitiesJul 24, 20262 min read

Crafted SVG files allow remote command execution as SYSTEM on Microsoft Bing servers

馃毃 Critical vulnerability discovered in Microsoft Bing Images. Attackers can execute arbitrary code over a network by using specially crafted SVG files.

criticalExploited VulnerabilitiesJul 21, 20262 min read

Exploitation of SharePoint deserialization flaw enables remote code execution and machine key theft

Attackers are exploiting a critical deserialization flaw in on-premise Microsoft SharePoint deployments to execute code and steal machine keys.

highExploited VulnerabilitiesJul 21, 20263 min read

Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw

A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.

criticalExploited VulnerabilitiesJul 16, 20262 min read

Attackers exploit unauthenticated remote code execution vulnerabilities in Microsoft SharePoint environments

馃毃 Critical remote code execution is being actively exploited in Microsoft SharePoint environments.

highExploited VulnerabilitiesJul 16, 20262 min read

Authenticated Site Owners exploit SharePoint deserialization flaw to execute remote code

Attackers are actively exploiting a critical remote code execution flaw in Microsoft SharePoint.

highData BreachesJul 15, 20263 min read

Exploitation of SharePoint vulnerabilities enables remote code execution and sensitive IIS key theft

Threat actors are actively exploiting three vulnerabilities in on-premises Microsoft SharePoint Server instances to achieve remote code execution and steal sensitive IIS machine keys.

highExploited VulnerabilitiesJul 15, 20262 min read

Local users can load administrative hives via Windows User Profile Service zero-day

A new zero-day vulnerability in the Windows User Profile Service allows local users to load administrative user hives.

highExploited VulnerabilitiesJul 14, 20262 min read

Active exploitation of two zero-day flaws drives massive Microsoft security update targeting 622 vulnerabilities

Microsoft has released a massive update addressing 622 vulnerabilities, including two zero-days currently being exploited in the wild.

highExploited VulnerabilitiesJul 14, 20262 min read

Authorized users can escalate local privileges via Microsoft Active Directory Federation Services vulnerability

An elevation of privilege vulnerability in Microsoft Active Directory Federation Services (AD FS) allows authorized users to gain higher privileges on local systems.

criticalExploited VulnerabilitiesJul 14, 20262 min read

Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation

A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network.

highExploited VulnerabilitiesJul 14, 20262 min read

Three zero-day vulnerabilities exploited in the wild require immediate Microsoft security updates

Microsoft's July 2026 Patch Tuesday addresses a record 570 flaws, including three zero-day vulnerabilities.

highExploited VulnerabilitiesJul 2, 20262 min read

Attackers exploit Microsoft SharePoint deserialization flaw to achieve remote code execution

Attackers are actively exploiting a high-severity deserialization flaw in Microsoft SharePoint to execute code remotely.

highAPT / Nation-StateJul 1, 20262 min read

Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers

Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.

highRansomwareJun 30, 20263 min read

Microsoft Defender BlueHammer Flaw Exploited for Ransomware Privilege Escalation

A vulnerability in Microsoft Defender Antimalware Platform (CVE-2026-33825), known as BlueHammer, has been exploited for privilege escalation in ransomware attacks.

highExploited VulnerabilitiesJun 9, 20263 min read

Zero-Day "RoguePlanet" Exploit in Microsoft Defender Grants SYSTEM Privileges on Patched Windows Systems

A new zero-day vulnerability named "RoguePlanet" in Microsoft Defender has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows

mediumExploited VulnerabilitiesJun 2, 20263 min read

Windows 10 Snipping Tool Vulnerability Enables Network Spoofing by Attackers

An unpatched vulnerability in Microsoft's Windows 10 Version 1607 Snipping Tool allows unauthorized actors to spoof over a network, posing medium severity risks.

criticalCloud SecurityMay 8, 20264 min read

Brief: Azure DevOps Information Disclosure Vulnerability Allows Network-Based Data Exposure

Microsoft disclosed an Azure DevOps vulnerability where exposure of sensitive information to an unauthorized actor could allow information disclosure over a network. NVD marks the record as an exclusively hosted service issue.

criticalCloud SecurityMay 8, 20264 min read

Defender Guidance: Azure DevOps Information Disclosure Vulnerability Allows Network-Based Data Exposure

Microsoft disclosed an Azure DevOps vulnerability where exposure of sensitive information to an unauthorized actor could allow information disclosure over a network. NVD marks the record as an exclusively hosted service issue.

criticalCloud SecurityMay 8, 20264 min read

Detection Notes: Azure DevOps Information Disclosure Vulnerability Allows Network-Based Data Exposure

Microsoft disclosed an Azure DevOps vulnerability where exposure of sensitive information to an unauthorized actor could allow information disclosure over a network. NVD marks the record as an exclusively hosted service issue.

criticalCloud SecurityMay 8, 20264 min read

Risk Brief: Azure DevOps Information Disclosure Vulnerability Allows Network-Based Data Exposure

Microsoft disclosed an Azure DevOps vulnerability where exposure of sensitive information to an unauthorized actor could allow information disclosure over a network. NVD marks the record as an exclusively hosted service issue.

highRansomwareMay 8, 20264 min read

Brief: Storm-1175 linked to Medusa ransomware deployment

Dark Reading reported that Microsoft linked a Medusa ransomware affiliate tracked as Storm-1175 to zero-day and n-day exploitation. The listing supports prioritizing exposure manag

highRansomwareMay 8, 20264 min read

Defender Guidance: Storm-1175 linked to Medusa ransomware deployment

Dark Reading reported that Microsoft linked a Medusa ransomware affiliate tracked as Storm-1175 to zero-day and n-day exploitation. The listing supports prioritizing exposure manag

highRansomwareMay 8, 20264 min read

Detection Notes: Storm-1175 linked to Medusa ransomware deployment

Dark Reading reported that Microsoft linked a Medusa ransomware affiliate tracked as Storm-1175 to zero-day and n-day exploitation. The listing supports prioritizing exposure manag

highRansomwareMay 8, 20264 min read

Risk Brief: Storm-1175 linked to Medusa ransomware deployment

Dark Reading reported that Microsoft linked a Medusa ransomware affiliate tracked as Storm-1175 to zero-day and n-day exploitation. The listing supports prioritizing exposure manag

highCloud SecurityMay 8, 20264 min read

Microsoft Teams Improper Authorization Vulnerability Could Disclose Information

Microsoft reported an improper authorization issue in Microsoft Teams that allows an authorized attacker to disclose information over a network.