Collected every two hours from specialised publications — each link leads to the original article.
Microsoft has recently rolled out the new version of its Edge browser. As announced, the new version comes with numerousMicrosoft Edge Now Alerts Users Of Brea…
If you have ever contacted Microsoft for support in the past 14 years, your technical query, along with some personally identifiable information might have bee…
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam mes…
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malici…
The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in …
Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to obse…
Microsoft on Monday attributed a threat actor it tracks as Storm-1175 to the exploitation of a critical security flaw in Fortra GoAnywhere software to facilita…
Cybersecurity researchers have detailed a new campaign dubbed OneClik that leverages Microsoft's ClickOnce software deployment technology and bespoke Golang ba…
Cybersecurity researchers have detailed a new campaign dubbed OneClik that leverages Microsoft's ClickOnce software deployment technology and bespoke Golang ba…
Microsoft has announced a new Windows Resiliency Initiative as a way to improve security and reliability, as well as ensure that system integrity is not compro…
A new attack technique could be used to bypass Microsoft's Driver Signature Enforcement (DSE) on fully patched Windows systems, leading to operating system (OS…
Microsoft has revealed that a financially motivated threat actor has been observed using a ransomware strain called INC for the first time to target the health…
The Microsoft Threat Intelligence team said it has observed a threat actor it tracks under the name Storm-1811 abusing the client management tool Quick Assist …
The U.S. Cyber Safety Review Board (CSRB) has criticized Microsoft for a series of security lapses that led to the breach of nearly two dozen companies across …
In January 2024, Microsoft discovered they’d been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). T…
Nation-state actors associated with Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) t…
Microsoft on Friday revealed that it was the target of a nation-state attack on its corporate systems that resulted in the theft of emails and attachments from…
Microsoft on Monday said it detected Kremlin-backed nation-state activity exploiting a now-patched critical security flaw in its Outlook email service to gain …
The prolific threat actor known asScattered Spiderhas been observed impersonating newly hired employees in targeted firms as a ploy to blend into normal on-hir…
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld.Cybersecurity firm…
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware calledLokiBoton compromised systems."Lok…