Microsoft

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware 2026-08-04 at 13:45 By Sinisa Markovic Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft […]

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware Read More »

Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft shortens NuGet API key lifetime to improve supply chain security 2026-08-04 at 11:30 By Anamarija Pogorelec Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for .NET developers. API keys created before August 17 […]

Microsoft shortens NuGet API key lifetime to improve supply chain security Read More »

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers 2026-08-04 at 08:18 By Eduard Kovacs The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek. This article is an excerpt […]

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Read More »

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking 2026-08-03 at 12:17 By Ionut Arghire Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking Read More »

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model 

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  2026-07-28 at 14:11 By Eduard Kovacs The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model  Read More »

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost 2026-07-27 at 22:23 By Sinisa Markovic Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the company stated that it went through review by […]

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS […]

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

Microsoft tightens Windows enterprise activation security

Microsoft tightens Windows enterprise activation security 2026-07-24 at 12:52 By Anamarija Pogorelec Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterprise activation security. Attestation will become mandatory with the […]

Microsoft tightens Windows enterprise activation security Read More »

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform 2026-07-20 at 09:00 By Anamarija Pogorelec Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package […]

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform Read More »

Microsoft makes Windows SSO prompts easier to manage

Microsoft makes Windows SSO prompts easier to manage 2026-07-16 at 11:47 By Anamarija Pogorelec Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue […]

Microsoft makes Windows SSO prompts easier to manage Read More »

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process 2026-07-16 at 10:45 By Anamarija Pogorelec Developers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host. […]

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process Read More »

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days 2026-07-14 at 21:50 By Ionut Arghire Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek. This article is an excerpt […]

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Read More »

No one knows how many old shims can still bypass UEFI Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot 2026-07-14 at 13:26 By Mirko Zorz The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot […]

No one knows how many old shims can still bypass UEFI Secure Boot Read More »

Microsoft Entra ID authentication overhaul to start in September 2026

Microsoft Entra ID authentication overhaul to start in September 2026 2026-07-14 at 11:49 By Anamarija Pogorelec Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time […]

Microsoft Entra ID authentication overhaul to start in September 2026 Read More »

Fake OAuth client IDs are helping attackers slip past sign-in logs

Fake OAuth client IDs are helping attackers slip past sign-in logs 2026-07-13 at 15:10 By Mirko Zorz Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as […]

Fake OAuth client IDs are helping attackers slip past sign-in logs Read More »

Microsoft demystifies how Windows updates work

Microsoft demystifies how Windows updates work 2026-07-13 at 08:30 By Anamarija Pogorelec Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly security updates, released […]

Microsoft demystifies how Windows updates work Read More »

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? 2026-07-10 at 10:30 By Help Net Security I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 […]

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? Read More »

Microsoft is rewriting Windows patch guidance because of AI

Microsoft is rewriting Windows patch guidance because of AI 2026-07-10 at 09:00 By Anamarija Pogorelec Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they […]

Microsoft is rewriting Windows patch guidance because of AI Read More »

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) 2026-07-09 at 15:14 By Zeljka Zorz Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before […]

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Read More »

20 open-source cybersecurity tools to keep your team ready for anything

20 open-source cybersecurity tools to keep your team ready for anything 2026-07-08 at 08:30 By Anamarija Pogorelec AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent […]

20 open-source cybersecurity tools to keep your team ready for anything Read More »

Scroll to Top