#microsoft
109 stories taggedmicrosoft.

Microsoft's AI bug-hunters logged 140 Windows CVEs in four months. The queue is now the problem.
FORGE Lab's agentic scanner is finding flaws faster than humans can validate and patch them, and the open-source world is feeling it too.

China-linked hackers posed as Anthropic staff to phish U.S. AI policy experts
A group tracked as TA419 ran fake-login pages that could capture passwords and the one-time codes meant to stop them.

Microsoft Pins Azure Wipeout on JadePuffer, the First Agentic Ransomware Crew
Storm-3168's AI-driven agents destroyed more than 100 Azure storage accounts in seven minutes, using a service principal whose credentials had been sitting in a public GitHub issue.

Microsoft names Storm-2570, the affiliate hopping between Qilin, DragonForce and other ransomware crews
The same intruder, the same toolkit, four different ransom notes. Microsoft says defenders who chase payloads keep missing the person behind them.

Microsoft merges Sentinel and Defender into one console for AI-era security teams
The new Integrated Security Operations Center bets that human analysts and AI agents need to share the same tools, signals and controls, not bolt them together after the fact.

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid
Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

When the AI Runs on Your Hardware, You Own the Security Problem
Microsoft says customers running AI on their own kit inherit a security job cloud providers used to handle. Here is what that actually means.

Microsoft Publishes a Cloud Web App Attack Playbook and Names the Weak Spots Nobody Wants to Own
Microsoft's new threat matrix organises how attackers actually break into cloud-hosted web apps, from forgotten DNS records to Kudu consoles left facing the internet.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

Windows 11 domain logins broke this week. Here is what actually happened.
A September 2026 security update quietly started enforcing an identity-protection feature. On the wrong kind of network, it locks staff out.

Microsoft fixes a perfect-10 flaw in Azure AI Foundry that let strangers take control
A missing authentication check in Microsoft's flagship AI development platform earned the rare CVSS 10.0 rating. Microsoft patched it on its side, but the bug says a lot about how fast AI services are shipping.

Microsoft's September 2026 Windows 11 update fixes 1,000 flaws and finally lets you move the taskbar
KB5124008 and KB5122880 ship a massive security backlog alongside a taskbar you can drag to any screen edge.

Microsoft ships final Windows 10 security rollup KB5122878 to ESU customers
The September 2026 update lands alongside a record Patch Tuesday fixing 966 flaws, and reaches only machines enrolled in Extended Security Updates or running the Enterprise LTSC editions.

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks
A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

Windows 11 to Tell Apps If You're a Child or Adult, Without Sharing Your Birthday
Microsoft's new age-awareness APIs return age bands rather than exact dates, and pair with a verify-once system tied to your Microsoft account.