Microsoft

Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks

Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks 2026-01-27 at 11:06 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21509 and it can be exploited to bypass security features.  The post Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks Read More »

Inside Microsoft’s veteran-to-tech workforce pipeline

Inside Microsoft’s veteran-to-tech workforce pipeline 2026-01-26 at 12:12 By Zeljka Zorz The technology workforce is changing, and military veterans are increasingly being recognized as one of the industry’s most valuable and dependable talent pools. In this Help Net Security interview, Chris Cortez, Vice President of Military Affairs at Microsoft and longtime leader of the Microsoft

Inside Microsoft’s veteran-to-tech workforce pipeline Read More »

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys 2026-01-26 at 10:52 By Sinisa Markovic Starting March 2026, Microsoft Entra ID will automatically enable passkey profiles and introduce support for synced passkeys. Passkey profiles move into general availability The update brings passkey profiles and synced passkeys into general availability. Administrators gain access to a new

Microsoft Entra ID will auto-enable passkey profiles, synced passkeys Read More »

Phishers Abuse SharePoint in New Campaign Targeting Energy Sector

Phishers Abuse SharePoint in New Campaign Targeting Energy Sector 2026-01-23 at 15:31 By Ionut Arghire Threat actors are leveraging the file-sharing service for payload delivery in AitM phishing and BEC attacks. The post Phishers Abuse SharePoint in New Campaign Targeting Energy Sector appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Phishers Abuse SharePoint in New Campaign Targeting Energy Sector Read More »

Microsoft introduces winapp, an open-source CLI for building Windows apps

Microsoft introduces winapp, an open-source CLI for building Windows apps 2026-01-23 at 07:24 By Anamarija Pogorelec Microsoft has released winapp, a new command line interface aimed at simplifying the process of building Windows applications. The open-source tool targets developers who rely on terminal based workflows and want a consistent way to create, configure, and manage

Microsoft introduces winapp, an open-source CLI for building Windows apps Read More »

Energy sector orgs targeted with AiTM phishing campaign

Energy sector orgs targeted with AiTM phishing campaign 2026-01-22 at 15:19 By Zeljka Zorz Organizations in the energy sector are being targeted with phishing emails aimed at compromising enterprise accounts, Microsoft warns. The attack campaign The attacks started with phishing emails with “NEW PROPOSAL – NDA” in the subject line, coming from a compromised email

Energy sector orgs targeted with AiTM phishing campaign Read More »

Microsoft updates the security baseline for Microsoft 365 Apps for enterprise

Microsoft updates the security baseline for Microsoft 365 Apps for enterprise 2026-01-22 at 01:13 By Anamarija Pogorelec Microsoft has published version 2512 of its security baseline for Microsoft 365 Apps for enterprise. The baseline documents recommended policy settings for Office applications used in enterprise environments and maps those settings to current management tools. What the

Microsoft updates the security baseline for Microsoft 365 Apps for enterprise Read More »

Microsoft shuts down RedVDS cybercrime subscription service tied to millions in fraud losses

Microsoft shuts down RedVDS cybercrime subscription service tied to millions in fraud losses 2026-01-15 at 10:22 By Sinisa Markovic Microsoft has announced a coordinated legal action in the United States and the United Kingdom to disrupt RedVDS, a global cybercrime subscription service tied to large-scale fraud losses. The effort forms part of a broader joint

Microsoft shuts down RedVDS cybercrime subscription service tied to millions in fraud losses Read More »

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement 2026-01-14 at 17:43 By Eduard Kovacs RedVDS enables threat actors to set up servers that can be used for phishing, BEC attacks, account takeover, and fraud. The post RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement appeared first on SecurityWeek. This article is an excerpt

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement Read More »

January 2026 Patch Tuesday forecast: And so it continues

January 2026 Patch Tuesday forecast: And so it continues 2026-01-09 at 11:26 By Help Net Security Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and

January 2026 Patch Tuesday forecast: And so it continues Read More »

Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks

Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks 2026-01-07 at 13:46 By Ionut Arghire Threat actors spoof legitimate domains to make their phishing emails appear to have been sent internally. The post Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks Read More »

Illegal streaming grew into an organized, profitable, and dangerous industry

Illegal streaming grew into an organized, profitable, and dangerous industry 2025-12-31 at 08:01 By Sinisa Markovic Rising streaming prices are pushing more viewers toward illegal options. Movies, TV shows, and live sports are now spread across multiple platforms, and keeping up with all of them is expensive. When something is easy to access, works smoothly,

Illegal streaming grew into an organized, profitable, and dangerous industry Read More »

Security teams debate how much to trust AI

Security teams debate how much to trust AI 2025-12-30 at 07:06 By Anamarija Pogorelec AI is reshaping how organizations operate, defend systems, and interpret risk. Reports reveal rising AI-driven attacks, hidden usage across enterprises, and widening gaps between innovation and security readiness. As adoption accelerates, companies face pressure to govern AI responsibly while preparing for

Security teams debate how much to trust AI Read More »

Microsoft Bug Bounty Program Expanded to Third-Party Code

Microsoft Bug Bounty Program Expanded to Third-Party Code 2025-12-12 at 13:01 By Ionut Arghire All critical vulnerabilities in Microsoft, third-party, and open source code are eligible for rewards if they impact Microsoft services. The post Microsoft Bug Bounty Program Expanded to Third-Party Code appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Microsoft Bug Bounty Program Expanded to Third-Party Code Read More »

Microsoft Names New Operating CISOs in Strategic Move to Strengthen Cyber Defense

Microsoft Names New Operating CISOs in Strategic Move to Strengthen Cyber Defense 2025-12-09 at 22:02 By Mike Lennon Microsoft’s Global CISO Igor Tsyganskiy announced several leadership updates across the security organization on Tuesday. “To better align cybersecurity defense of Microsoft, our customers, partners and ecosystem we are continuing to optimize my organization,” Tsyganskiy noted in

Microsoft Names New Operating CISOs in Strategic Move to Strengthen Cyber Defense Read More »

December 2025 Patch Tuesday forecast: And it’s a wrap

December 2025 Patch Tuesday forecast: And it’s a wrap 2025-12-08 at 09:56 By Help Net Security It’s hard to believe that we’re in December of 2025 already and the end of the year is fast approaching. Looking back on the year, there are two major items that really stand out in my mind. First, there

December 2025 Patch Tuesday forecast: And it’s a wrap Read More »

Microsoft Silently Mitigated Exploited LNK Vulnerability

Microsoft Silently Mitigated Exploited LNK Vulnerability 2025-12-03 at 14:35 By Ionut Arghire Windows now displays in the properties tab of LNK files critical information that could reveal malicious code. The post Microsoft Silently Mitigated Exploited LNK Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Silently Mitigated Exploited LNK Vulnerability Read More »

New “HashJack” attack can hijack AI browsers and assistants

New “HashJack” attack can hijack AI browsers and assistants 2025-11-26 at 14:18 By Zeljka Zorz Security researchers at Cato Networks have uncovered a new indirect prompt injection technique that can force popular AI browsers and assistants to deliver phishing links or disinformation (e.g., incorrect medicine dosage guidance or investment advice), send sensitive data to the

New “HashJack” attack can hijack AI browsers and assistants Read More »

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature 2025-11-24 at 15:32 By Ionut Arghire Without proper security controls, AI agents could perform malicious actions, such as data exfiltration and malware installation. The post Microsoft Highlights Security Risks Introduced by New Agentic AI Feature appeared first on SecurityWeek. This article is an excerpt from

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature Read More »

Scroll to Top