Tag

#microsoft

108 stories taggedmicrosoft · page 5 of 8.

Azure cloud platform dashboard on a monitor displaying automation settings, with default configuration options highlighted and exposed identity credentials visi
Vulnerabilities

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity

A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

3 min read
Bing image search interface on a monitor with a malicious SVG file uploaded and processed, server room in background suggesting Microsoft infrastructure, comman
Vulnerabilities

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers

Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

3 min read
A Microsoft Teams chat window with hundreds of unread phishing messages flooding across the screen simultaneously, while a timeline graph beside it shows a shar
Threat Intelligence

After Tycoon2FA Was Shut Down, Phishing Criminals Went Looking for New Tricks

Microsoft's Q2 2026 email threat report shows that busting a major phishing-for-hire service slashed attack volume by 92%, but criminals quickly pivoted to Microsoft Teams chats and automated campaigns that hit tens of thousands of organisations in hours.

4 min read
Windows 11 login screen displaying the new passkey system interface, with security research documents showing three discovered flaws spread across a desk beside
Identity & Access

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again

A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default sign-in method for hundreds of millions of users.

4 min read
An email server room with glowing equipment showing quarantine status indicators, mailboxes shown as locked containers on digital displays, calendar and email f
Cloud Security

Microsoft Exchange Online is Wrongly Locking Away Customer Mailboxes

A memory bug from an infrastructure change has been quarantining legitimate mailboxes since Sunday, blocking email and calendar access with no full-fix timeline yet.

3 min read
A busy IT operations center with security team members reviewing patch notes and discussing timelines on whiteboards and dashboards, with tension visible as cal
Vulnerabilities

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.

Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

4 min read
Illustration: a developer's dual-monitor desk at dusk
AI Security

A Hidden Comment in Azure DevOps Can Trick an AI Reviewer Into Stealing Code

Microsoft's official Azure DevOps MCP server passes pull request descriptions to AI agents without checking for hidden instructions, letting an outsider steer a reviewer's assistant into private projects.

3 min read
Illustration: a dimly lit corporate server room, rows of rack-mounted servers with amber and red status LEDs glowing
Vulnerabilities

Microsoft admits Windows update server sync has been broken for over a week

WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

4 min read
Illustration: a laptop screen showing a fake browser error dialog with a copy-paste instruction box, warm desk lamp light
Identity & Access

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers

The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

4 min read
Illustration: a darkened office workstation showing a Windows-
Vulnerabilities

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs

A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

4 min read
An office worker's computer screen showing multiple cloud application windows open simultaneously with sensitive customer data visible in each, filing cabinets
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
Illustration: a modern laptop on a plain desk, screen showing a generic blue software update progress bar without any brand
Policy & Regulation

Windows 11 24H2 Home and Pro users have three months before security updates stop

Microsoft has set 13 October 2026 as the cut-off for monthly patches on Windows 11 24H2 Home and Pro, and on Windows 10 Enterprise LTSB 2016.

3 min read
Illustration: a close-up Windows laptop screen showing a generic blue security shield icon glowing
Vulnerabilities

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System

Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

3 min read
Illustration: a darkened server room with a single Windows laptop open on a rack shelf
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Illustration: a dimly lit server rack in a corporate data centre, blue and amber status LEDs glowing
Vulnerabilities

CISA sounds alarm on SharePoint Server flaws being used to break in right now

The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

3 min read
© 2026 Threat Vectr