Microsoft

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

Ravie LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that…

2 jours ago

It’s Patch Tuesday for Microsoft and Not a Zero-Day In Sight

For the first time in nearly two years, Microsoft's monthly security update featured no actively exploited zero-day vulnerabilities or previously…

5 jours ago

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a…

2 semaines ago

Microsoft Edge Stores Passwords in Process Memory, Posing Risk

An attacker with administrative privileges can gain access to Microsoft Edge user passwords even when they're not in use, because…

2 semaines ago

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

Ravie LakshmananApr 28, 2026Vulnerability / Identity Management An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID…

3 semaines ago

UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware

A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to…

3 semaines ago

Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

Ravie LakshmananApr 22, 2026Cyber Espionage / Malware The threat actor known as Harvester has been attributed to a new Linux…

4 semaines ago

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Ravie LakshmananApr 17, 2026Vulnerability / Endpoint Security Huntress is warning that threat actors are exploiting three recently disclosed security flaws…

1 mois ago

Microsoft, Salesforce Patch AI Agent Data Leak Flaws

One aspect of the "AI revolution" keeping security professionals up at night is the continued prevalence of prompt injection attacks…

1 mois ago