The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Nation-state actors associated with Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) t…
A newly disclosed security flaw in the Microsoft Defender SmartScreen has been exploited as a zero-day by an advanced persistent threat actor called Water Hydr…
Multiple vulnerabilities have been discovered in Microsoft Edge, the worst of which could lead to remote code execution.
Microsoft on Friday revealed that it was the target of a nation-state attack on its corporate systems that resulted in the theft of emails and attachments from…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability impacting Microsoft SharePoint Server to its Known…
Microsoft has addressed a total of 48 security flaws spanning its software as part of its Patch Tuesday updates for January 2024.Of the 48 bugs, two are rated …
A new phishing campaign is leveraging decoy Microsoft Word documents as bait to deliver a backdoor written in the Nim programming language."Malware written in …
Microsoft on Monday said it detected Kremlin-backed nation-state activity exploiting a now-patched critical security flaw in its Outlook email service to gain …
Microsoft has released fixes to address63 security bugsin its software for the month of November 2023, including three vulnerabilities that have come under act…
The Redmond giant has recently announced introducing a new privacy feature to its authenticator app.…Microsoft Authenticator Restricts Suspicious MFA Notificat…
The prolific threat actor known asScattered Spiderhas been observed impersonating newly hired employees in targeted firms as a ploy to blend into normal on-hir…
Microsoft has linked the exploitation of a recently disclosed critical flaw in Atlassian Confluence Data Center and Server to a nation-state actor it tracks as…
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
In a recent phishing campaign, the researchers noticed the use of the long-known ZeroFont phishing…Hackers Use ZeroFont Phishing To Target Microsoft Outlook Us…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld.Cybersecurity firm…
Researchers discovered a reply URL flaw in Azure AD that could allow unauthorized access to…Microsoft Power Platform API Threatened Due To Reply URL Flaw on La…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddeda recently patched security flaw in Microsoft's .NET and Visual Studio products to its…
Microsoft is warning of the threat malicious cyber actors pose tostadium operations, noting that the cyber risk surface of live sporting events is "rapidly exp…
Microsoft on Wednesday announced that it's expanding cloud logging capabilities to help organizations investigate cybersecurity incidents and gain more visibil…
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware calledLokiBoton compromised systems."Lok…
The July 2023 Patch Tuesday update bundle patched at least six different actively-exploited vulnerabilities across…Microsoft July Patch Tuesday Fixed Six Zero-…
Microsoft on Tuesdayrevealedthat it repelled a cyber attack staged by a Chinese nation-state actor targeting two dozen organizations, some of which include gov…