Microsoft

OneDrive updates focus on AI, access control, and compliance

OneDrive updates focus on AI, access control, and compliance 2026-04-22 at 13:48 By Anamarija Pogorelec Microsoft OneDrive’s recent updates focus on improving intelligence, collaboration, and administrative control. “Last year, we made a promise: your files should work for you, not the other way around. That meant reimagining OneDrive not just as a place to store […]

OneDrive updates focus on AI, access control, and compliance Read More »

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild 2026-04-17 at 14:32 By Zeljka Zorz The security researcher who earlier this month published a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability in Microsoft Defender is back with two more. The first, dubbed “RedSun,” is another privilege escalation flaw […]

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild Read More »

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest 2026-04-16 at 15:03 By Eduard Kovacs Researchers found more than 80 high-impact cloud and AI vulnerabilities during the event, which had a $5 million prize pool. The post Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest appeared first on […]

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest Read More »

Windows is getting stronger RDP file protections to fight phishing attacks

Windows is getting stronger RDP file protections to fight phishing attacks 2026-04-16 at 01:19 By Sinisa Markovic Microsoft has introduced new Windows protections starting with the April 2026 security update to reduce phishing attacks that abuse Remote Desktop (.rdp) files. With these updates, the Remote Desktop Connection app displays stronger warning dialogs before a connection […]

Windows is getting stronger RDP file protections to fight phishing attacks Read More »

Microsoft ends desktop detour for sensitivity labels in Office web apps

Microsoft ends desktop detour for sensitivity labels in Office web apps 2026-04-15 at 01:42 By Sinisa Markovic Microsoft is rolling out an update to Office for the web that removes a long-standing limitation around document protection, adding new control to browser-based apps. Specifying users in the Permissions dialog (Source: Microsoft) Users can now apply sensitivity […]

Microsoft ends desktop detour for sensitivity labels in Office web apps Read More »

Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities

Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities 2026-04-14 at 22:26 By Eduard Kovacs Experts say this is the second-largest Microsoft Patch Tuesday ever based on CVE count. The post Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities Read More »

BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings

BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings 2026-04-13 at 17:31 By Kevin Townsend Claims that “Microsoft is running one of the largest corporate espionage operations in modern history” face scrutiny as researchers analyze LinkedIn’s browser extension probing The post BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings appeared first on […]

BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings Read More »

AI-enabled device code phishing campaign exploits OAuth flow for account takeover

AI-enabled device code phishing campaign exploits OAuth flow for account takeover 2026-04-07 at 14:59 By Anamarija Pogorelec A phishing campaign that bypasses the standard 15-minute expiration window through automation and dynamic code generation, leveraging the OAuth Device Code Authentication flow to compromise organizational accounts at scale, has been observed by the Microsoft Defender Security Research […]

AI-enabled device code phishing campaign exploits OAuth flow for account takeover Read More »

GitHub Copilot CLI gets a second-opinion feature built on cross-model review

GitHub Copilot CLI gets a second-opinion feature built on cross-model review 2026-04-07 at 12:56 By Anamarija Pogorelec Coding agents make decisions in sequence: a plan is drafted, implemented, then tested. Any error introduced early compounds as subsequent steps build on the same flawed assumption. Self-reflection is a recognized mitigation technique, and one GitHub Copilot already […]

GitHub Copilot CLI gets a second-opinion feature built on cross-model review Read More »

Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approaches

Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approaches 2026-04-03 at 14:57 By Anamarija Pogorelec Microsoft’s Secure Boot certificates, issued in 2011, are approaching expiration in 2026. To help IT administrators track whether devices have received replacement certificates, Microsoft has added new status indicators to the Windows Security app, under Device […]

Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approaches Read More »

Microsoft releases open-source toolkit to govern autonomous AI agents

Microsoft releases open-source toolkit to govern autonomous AI agents 2026-04-03 at 08:39 By Anamarija Pogorelec AI agents can book travel, execute financial transactions, write and run code, and manage infrastructure without human intervention at each step. Frameworks like LangChain, AutoGen, CrewAI, and Azure AI Foundry Agent Service have made this kind of autonomy straightforward to […]

Microsoft releases open-source toolkit to govern autonomous AI agents Read More »

Microsoft adds high-volume email sending to Exchange Online

Microsoft adds high-volume email sending to Exchange Online 2026-04-02 at 07:58 By Anamarija Pogorelec Organizations that rely on Exchange Online for internal communications have long needed a way to send large volumes of automated messages, such as payroll notifications, IT alerts, and security advisories, without running into the sending limits designed for person-to-person email. Microsoft […]

Microsoft adds high-volume email sending to Exchange Online Read More »

Windows 11 gets a rebuilt console engine with regex search, Sixel images and a 10x speed boost

Windows 11 gets a rebuilt console engine with regex search, Sixel images and a 10x speed boost 2026-03-31 at 16:05 By Anamarija Pogorelec Microsoft released Windows 11 Insider Preview Build 29558.1000 to the Canary Channel, part of the optional 29500 build series. The build carries a set of changes focused on the Windows Console, a […]

Windows 11 gets a rebuilt console engine with regex search, Sixel images and a 10x speed boost Read More »

Microsoft hands Entra ID users new option for MFA

Microsoft hands Entra ID users new option for MFA 2026-03-25 at 12:46 By Anamarija Pogorelec Organizations rely on MFA to enforce identity checks before granting access to systems and services. Microsoft has made external MFA generally available in Microsoft Entra ID, expanding support for third-party identity providers. Configure external MFA in Microsoft Entra ID (Source: […]

Microsoft hands Entra ID users new option for MFA Read More »

Microsoft details AI prompt abuse techniques targeting AI assistants

Microsoft details AI prompt abuse techniques targeting AI assistants 2026-03-24 at 14:02 By Anamarija Pogorelec Prompt abuse occurs when crafted inputs manipulate an AI system into producing unintended behavior, such as attempting to access sensitive information or overriding built-in safety instructions. Prompt injection is also recognized as one of the top risks in the 2025 […]

Microsoft details AI prompt abuse techniques targeting AI assistants Read More »

Secure endpoint management systems immediately, CISA urges

Secure endpoint management systems immediately, CISA urges 2026-03-19 at 14:59 By Sinisa Markovic The US Cybersecurity and Infrastructure Security Agency (CISA) warns that the cyberattack on Stryker Corporation serves as a signal to U.S. organizations that foreign cyber activity tied to Middle East conflicts may be spilling into their operations. Attackers breached Stryker’s internal Microsoft […]

Secure endpoint management systems immediately, CISA urges Read More »

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) 2026-03-19 at 13:32 By Zeljka Zorz CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers. The confirmation comes from the US Cybersecurity and Infrastructure Security Agency (CISA), which added the flaw to its Known Exploited Vulnerabilities […]

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) Read More »

Major tech companies invest $12.5 million in open source security

Major tech companies invest $12.5 million in open source security 2026-03-18 at 11:31 By Sinisa Markovic The Linux Foundation announced $12.5 million in grant funding backed by Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI to strengthen open source security. The funding will be directed through the foundation’s Alpha-Omega Project and the Open Source […]

Major tech companies invest $12.5 million in open source security Read More »

Google, Meta, Microsoft Among Signatories of Pact to Combat Scams

Google, Meta, Microsoft Among Signatories of Pact to Combat Scams 2026-03-17 at 14:26 By Eduard Kovacs Several major tech and retail companies have signed an industry accord against online scams and fraud. The post Google, Meta, Microsoft Among Signatories of Pact to Combat Scams appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Google, Meta, Microsoft Among Signatories of Pact to Combat Scams Read More »

Microsoft zeroes in on AI-driven data risks in Fabric

Microsoft zeroes in on AI-driven data risks in Fabric 2026-03-17 at 12:21 By Anamarija Pogorelec New Microsoft Purview innovations for Microsoft Fabric help organizations secure data and accelerate AI adoption. The updates focus on identifying risks, preventing data oversharing, and strengthening governance and data quality across the data estate. Integration between Microsoft Purview and Microsoft […]

Microsoft zeroes in on AI-driven data risks in Fabric Read More »

Scroll to Top