Skip to main content

Tag: microsoft

702 articles

Shadowy figure looms behind a login page on a laptop screen, poised to submit credentials.

VENOM Phishing Attacks Target C-Suite Microsoft Logins

A new phishing-as-a-service platform called VENOM is making it alarmingly easy for hackers to target senior executives, specifically seeking their Microsoft logins. This compact toolkit is putting the keys to the corner office within reach of any motivated adversary, leaving security teams scrambling to respond.

Analyst 207
Ominous cloud looms over government building with broken lock and shadowy device displaying sensitive data.

Microsoft Cloud Security Falls Short in Government Review

A scathing government review has revealed that Microsoft's cloud security documentation is woefully inadequate, leaving evaluators with a disturbing lack of confidence in the system's overall security posture. This shocking finding raises serious concerns about the reliability of one of Microsoft's largest cloud offerings.

Analyst 207
Lone laptop with faint padlock reflection sits on damaged concrete amidst shattered glass and wires under ominous cloudy sky.

Microsoft Cloud Security Review Exposes Gaps in Protection

A scathing internal government review of Microsoft's cloud security offering revealed alarming gaps in protection, with evaluators unable to determine whether sensitive information was safe as it moved across servers. The review team was left frustrated by a lack of proper detailed security documentation.

Analyst 207
Diverse group of open-source developers blocked by a faceless figure at a locked gate.

Microsoft Abruptly Bans Top Open-Source Developers

Imagine being a leading open-source developer, only to be suddenly and silently locked out of your Microsoft developer account, with no warning, no emails, and no human contact - just automated blocks and a lengthy appeal wait. This is what recently happened to the creators of VeraCrypt and WireGuard, leaving their critical projects in limbo.

Analyst 207
Locked rusty gate in front of ominous tech company HQ at dusk with scattered, wilting open-source symbols nearby.

Microsoft Disrupts Open-Source Projects with Sudden Account Suspensions

Microsoft's sudden suspension of developer accounts has left maintainers of popular open-source projects locked out, unable to publish crucial security patches and software updates for Windows users. This abrupt move has sparked concern, with many wondering who will keep the digital roof fixed when the people who make the essential tools are shut out.

Analyst 207
Fortified underground datacenter with server racks, surrounded by sandbags and barbed wire, under flickering emergency…

Microsoft Rethinks Datacenter Design Amid Conflict Zone Threats

Microsoft is rethinking its datacenter design in conflict-prone regions after recent strikes put these critical facilities at risk, sparking concerns about the resilience of the clouds they support. The company's president, Brad Smith, is leading the effort to reevaluate and revamp its approach to building and protecting datacenters in volatile areas.

Analyst 207
Person puzzled in front of laptop with disrupted Windows start menu on screen.

Microsoft Deploys Fix for Windows Start Menu Search Disruption

Microsoft has swiftly deployed a server-side fix to resolve a frustrating issue that left some Windows 11 23H2 users unable to access the Start Menu search feature. This quick action means you should now be able to search with ease again.

Analyst 207
Worn router on a desk surrounded by candles with a looming Russian shadow.

NCSC Warns of Russia's Ongoing Router Exploits

Russia's notorious hackers, Fancy Bear, are exploiting routers to steal passwords and sensitive information, compromising the security of countless individuals and organisations. With around 5,000 devices and 200 organisations already affected, experts warn that this latest threat is one to take seriously.

Analyst 207
Cracked laptop screen with eerie glow, snake-like cord morphing into menacing stone face.

Microsoft Uncovers Storm-1175's Medusa Ransomware Link

Microsoft just dropped a crucial report linking Storm-1175, a notorious threat actor, to high-velocity Medusa ransomware attacks that exploit flaws in networked systems. This newly uncovered connection raises the alarm for anyone building, defending, or relying on these systems to stay vigilant against Medusa ransomware attacks.

Analyst 207
Microsoft Resolves Outlook Email Delivery Bug

Microsoft Resolves Outlook Email Delivery Bug

Good news for Classic Outlook users on Outlook.com - Microsoft has fixed a frustrating bug that was preventing some users from sending emails, leaving them stuck in the outbox. The issue, now resolved, was affecting a subset of users, but thankfully, it's been successfully remedied.

Analyst 207
Windows Zero-Day Exploit Leaked, Enables Instant Admin Access

Windows Zero-Day Exploit Leaked, Enables Instant Admin Access

A disgruntled researcher has leaked working exploit code for a previously unknown Windows vulnerability, dubbed BlueHammer, allowing attackers to instantly gain administrator access to any system. This alarming development comes after the researcher privately submitted the flaw to Microsoft, which had not yet patched the vulnerability.

Analyst 207
Microsoft Deprecates Support Tool in Windows Updates

Microsoft Deprecates Support Tool in Windows Updates

Microsoft just pulled the plug on the Support and Recovery Assistant (SaRA) command-line utility, a trusted tool for diagnosing and repairing Windows systems, from all supported Windows updates as of March 10. This small change could have big operational consequences for users relying on this tool.

Analyst 207
Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Meet Storm-1175, a China-based cybercriminal group linked to the notorious Medusa ransomware gang, who's rapidly exploiting vulnerabilities to wreak havoc. This financially motivated group is marrying fast-moving zero-day exploits with Medusa ransomware, leading to a sharp escalation in attacks.

Analyst 207
LinkedIn Harvests Browser Data with Secret Chrome Extension Scans

LinkedIn Harvests Browser Data with Secret Chrome Extension Scans

A recent report, dubbed BrowserGate, uncovers LinkedIn's hidden practice of scanning visitors' browsers for installed extensions and harvesting device data, raising serious questions about user privacy. The professional social network reportedly checks for over 6,000 Chrome extensions, leaving users to wonder: what should LinkedIn know about your browser?

Analyst 207
LinkedIn Harvests Browser Data with Secret JavaScript Scripts

LinkedIn Harvests Browser Data with Secret JavaScript Scripts

Did you know that LinkedIn is quietly harvesting browser data, including a list of your installed Chrome extensions, every time you load a page? A recent analysis, dubbed BrowserGate, uncovered the surprising truth behind LinkedIn's use of secret JavaScript scripts to scan visitor browsers.

Analyst 207
Microsoft Grapples with Weeks-Long Exchange Online Mailbox Access Disruptions

Microsoft Grapples with Weeks-Long Exchange Online Mailbox Access Disruptions

Weeks of frustrating disruptions have left Outlook mobile and macOS users struggling to access their Exchange Online mailboxes, sparking a flurry of questions about reliability and resolution. Microsoft is actively investigating the issue, but for affected users, the wait for a fix continues.

Analyst 207
Microsoft Accelerates Windows 11 Upgrades with Mandatory 25H2 Rollout

Microsoft Accelerates Windows 11 Upgrades with Mandatory 25H2 Rollout

Microsoft is taking a bold step by automatically upgrading unmanaged Windows 11 devices running 24H2 Home and Pro editions to the latest 25H2 version, starting this week. This move marks a significant shift in the company's approach to Windows 11 upgrades.

Analyst 207
Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft is investigating a frustrating issue affecting Classic Outlook users, preventing them from sending emails via Outlook.com due to a bug linked to broader email delivery problems. The disruption is causing inconvenience for users relying on seamless communication.

Analyst 207
Dimly lit desk with laptop showing fake login page, surrounded by clutter and a suspicious smartphone message.

EvilTokens Fuels Sophisticated Microsoft Phishing Attacks

This month, a commercially available toolkit called EvilTokens made it alarmingly easy for fraudsters to launch sophisticated Microsoft phishing attacks, putting corporate email systems and Microsoft accounts directly in their crosshairs. By exploiting device code authentication, a feature designed to simplify login, EvilTokens has turned a convenient tool into a potent weapon for organized cybercrime.

Analyst 207
Smartphone lies on shattered Windows desktop screen amidst binary code fragments, surrounded by a vulnerable cityscape at…

Microsoft Flags WhatsApp-Delivered VBS Malware Bypassing Windows UAC

Beware of WhatsApp attachments from familiar numbers - they might be malicious VBS files designed to quietly hijack your Windows system. A sneaky new campaign uses decades-old scripting language to bypass Windows UAC and give attackers remote access.

Analyst 207
Microsoft Issues Emergency Patch for Windows 11 Update Glitch

Microsoft Issues Emergency Patch for Windows 11 Update Glitch

Thousands of IT admins faced a nightmare when a recent Windows 11 update caused installation failures, but Microsoft swiftly came to the rescue with an emergency patch to fix the glitch. The surprise repair update addresses issues introduced by the March 2026 non-security preview update, ensuring a smooth rollout for users.

Analyst 207
Cybersecurity team rapidly responds to threats in a futuristic, high-tech security operations center.

Critical AI SOC Funding Fuels Faster Threat Response

Cyber attacks can linger undetected for weeks, causing devastating damage - but what if your security team could respond faster and more effectively? Tenex's AI-enhanced Security Operations Center platform is tackling this challenge head-on, and a recent $250 million Series B funding round is poised to supercharge its mission.

Analyst 207
WhatsApp Abused in Critical Multi-Stage Attack Warns Microsoft

WhatsApp Abused in Critical Multi-Stage Attack Warns Microsoft

Beware: a simple WhatsApp message can be the gateway for hackers to take control of your entire corporate network, as Microsoft warns of a new multi-stage social-engineering campaign exploiting the popular messaging app's security vulnerabilities. Stay vigilant - your harmless "ping" could be the weakest link in your security chain!

Analyst 207
Microsoft Patches Critical Zero-Day Flaws in February Update

Microsoft Patches Critical Zero-Day Flaws in February Update

Microsoft just dropped a crucial update to fix over 50 security flaws, including six critical zero-day vulnerabilities that hackers are already exploiting - leaving no time to waste in patching your systems to stay protected. Don't let cyber threats leave you vulnerable, stay ahead of the game with timely updates and safeguards.

Analyst 207