#microsoft
102 stories taggedmicrosoft · page 2 of 7.

Windows 10 gets its August 2026 security patch: what KB5120249 actually fixes
Microsoft's monthly update lands with a backup fix and wider Secure Boot certificate rollout. Install it.

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame
Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

Ransomware crews are now breaking into SharePoint servers through a May flaw
CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

Swiss federal IT office says SharePoint breach exposed 200 accounts
The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

Cybersecurity Groups Draft 'SAFE' Rules for Sharing AI Incident Data
A coalition of more than 120 companies, including Nvidia, Cisco and Amazon, is asking for public feedback on a proposed framework that would let organisations quietly report AI security failures and share what they learned with everyone else.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

Azure Cosmos DB Flaw Let Researchers Reach Any Customer's Database
Wiz says its 'CosmosEscape' exploit chain broke out of a query sandbox and grabbed a master key that unlocked databases across Microsoft's cloud. Microsoft has patched it.

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control
Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.

Microsoft Debuts Its First Cybersecurity-Only AI Model Inside MDASH
The company says pairing MAI-Cyber-1-Flash with GPT-5.4 scored 95.95% on CyberGym at half the cost of its previous best setup.

Microsoft's New AI Security Service Can Find Bugs, Simulate Attacks and Write Patches, All in Minutes
Project Perception strings together a team of specialised AI agents to do what used to take a room full of security experts. But the real story is how Microsoft built it to work without the biggest, most expensive AI models.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers
Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

After Tycoon2FA Was Shut Down, Phishing Criminals Went Looking for New Tricks
Microsoft's Q2 2026 email threat report shows that busting a major phishing-for-hire service slashed attack volume by 92%, but criminals quickly pivoted to Microsoft Teams chats and automated email campaigns that hit tens of thousands of organisations in hours.