Microsoft

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products 2026-09-18 at 13:57 By Eduard Kovacs Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Read More »

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? 2026-09-15 at 23:24 By Associated Press Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech […]

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? Read More »

Microsoft sets security and safety rules for its AI models

Microsoft sets security and safety rules for its AI models 2026-09-15 at 13:50 By Anamarija Pogorelec Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six […]

Microsoft sets security and safety rules for its AI models Read More »

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints 2026-09-15 at 12:40 By Eduard Kovacs The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek. […]

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints Read More »

Attackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers call employees’ personal phones to break into Microsoft 365 accounts 2026-09-10 at 16:26 By Sinisa Markovic Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email […]

Attackers call employees’ personal phones to break into Microsoft 365 accounts Read More »

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor 2026-09-09 at 12:04 By Zeljka Zorz September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing […]

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor Read More »

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days 2026-09-08 at 22:20 By Ionut Arghire The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Read More »

Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft’s Project Zenith puts large AI models directly on developer PCs 2026-09-08 at 07:30 By Anamarija Pogorelec Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB […]

Microsoft’s Project Zenith puts large AI models directly on developer PCs Read More »

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast: All we need is more time 2026-09-04 at 09:00 By Help Net Security The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: […]

September 2026 Patch Tuesday forecast: All we need is more time Read More »

Windows memory integrity switches on automatically for eligible devices in October 2026

Windows memory integrity switches on automatically for eligible devices in October 2026 2026-09-03 at 07:30 By Anamarija Pogorelec Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory […]

Windows memory integrity switches on automatically for eligible devices in October 2026 Read More »

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 2026-09-02 at 16:24 By Sinisa Markovic Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 […]

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Read More »

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft Rolls Out 22 Fresh Security Patches 2026-08-21 at 11:12 By Ionut Arghire Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Rolls Out 22 Fresh Security Patches Read More »

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 2026-08-19 at 13:37 By Ionut Arghire The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Read More »

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) 2026-08-13 at 16:05 By Sinisa Markovic Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday […]

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) Read More »

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day 2026-08-11 at 21:46 By Ionut Arghire A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from […]

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Read More »

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users 2026-08-10 at 16:19 By Sinisa Markovic Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting […]

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users Read More »

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 2026-08-10 at 14:34 By Zeljka Zorz To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. […]

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 Read More »

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. […]

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

Microsoft, Apple Release Fresh Security Updates

Microsoft, Apple Release Fresh Security Updates 2026-08-07 at 12:09 By Ionut Arghire Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft, Apple Release Fresh Security Updates Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs […]

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

Scroll to Top