Tag: microsoft
702 articles

Microsoft Releases KB5120249 Update to Fix Security Vulnerabilities
Microsoft just dropped a crucial update, KB5120249, for Windows 10 versions 22H2 and 21H2, squashing security vulnerabilities and pesky bugs that could compromise your system. This August 2026 cumulative update tackles major issues like File History backup failures and expands Secure Boot certificate coverage.

Microsoft Releases Patch Tuesday Updates to Fix 400 Vulnerabilities
Microsoft just dropped a massive security update, addressing a whopping 400 vulnerabilities with its August 2026 Patch Tuesday release - and it's a mandatory install to keep your system safe. You can grab the update via Windows Update or by downloading it directly from the Microsoft Update Catalog.

Researchers Expose Windows 11 Vulnerability in USB Auto-Install Feature
Security researchers have uncovered a vulnerability in Windows 11's USB auto-install feature, allowing an unprivileged user to execute SYSTEM-level code on a fully updated machine. This clever hack, dubbed "Plug And Pwn," exploits the Plug and Play auto-install process to gain elevated access.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access
Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Swiss Government SharePoint Breach Exposes 200 Accounts
The Swiss government's Microsoft SharePoint system was breached, compromising the login credentials of around 200 accounts, after security specialists detected unusual activity on July 28. The breach was quickly contained and remediated, with external internet access to the SharePoint environment blocked and patches applied.

Microsoft Boosts Bug Bounty Payouts to Record $20 Million
Microsoft just made it very rewarding to be a security researcher, shelling out a record $20 million in bug bounties to 562 talented individuals who helped the company squash vulnerabilities. That's a big jump from last year's $17 million, and a testament to the power of AI-driven security research!

Microsoft Secure Boot Vulnerability Exposed After 13 Years
A shocking security vulnerability in Microsoft's Secure Boot, a safeguard designed to protect Windows and Linux devices from firmware infections, has been easily exploitable for 13 of its 14 years of existence. Researchers uncovered 11 defective firmware images, some dating back to 2013, that were still publicly available and signed by Microsoft, making it alarmingly simple to bypass the security measure.

Russian Hackers Exploit Exchange Zero-Day for Long-Term Mailbox Access
Russian hackers have unleashed a powerful tool, dubbed OWAReaper, exploiting a zero-day flaw in Exchange Outlook Web Access to gain long-term access to mailboxes, with Proofpoint hailing it as the most sophisticated backdoor delivered via half-click exploits they've ever seen. The attack, linked to the Russian state-sponsored group Laundry Bear, cleverly uses a cross-site scripting flaw to execute arbitrary JavaScript in victims' browsers.

Microsoft Releases KB5101684 Update, Bolstering Windows 11 Security and Fixes
Microsoft just dropped a new update, KB5101684, for Windows 11, packing 42 bug fixes and snappy new features to take your experience to the next level. This July 2026 optional non-security preview release is a sneak peek at what's coming next in August's Patch Tuesday.

Microsoft Unveils AI-Powered Security Tools to Counter Emerging Threats
Microsoft is fighting back against emerging threats with AI-powered security tools, leveraging the power of agentic AI to help defenders stay one step ahead. By deploying specialized "red, blue, and green" agents, the company's new Project Perception system continuously identifies, evaluates, and reduces security risks.

Microsoft Unveils AI-Powered Cybersecurity Tools in Heated Market
Microsoft just launched Project Perception, an AI-powered security platform that supercharges cyber defense by merging multiple components into a continuously learning system that can reason, prioritize, and act at lightning-fast machine speed. This game-changing tech combines human oversight with powerful automation to revolutionize the way we fight cyber threats.

Microsoft Unveils AI Model Boosting Vulnerability Detection to 95.95% at Lower Cost
Microsoft's new AI model, MAI-Cyber-1-Flash, paired with GPT-5.4, has achieved a remarkable 95.95% vulnerability detection rate at nearly half the cost of its previous system. This game-changing tech, integrated into MDASH, is revolutionizing cybersecurity with faster and more affordable threat detection.

Certighost Exploit Hijacks Windows Domains With Authenticated Attacks
Beware of the Certighost exploit, a sneaky attack that lets hackers hijack Windows domains by manipulating machine account attributes and snagging authentication certificates. This vulnerability, tracked as CVE-2026-54121, was patched in July 2026, but not before security researchers publicly disclosed its technical details.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals
Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

ChatGPT Enters Top 10 Most Impersonated Brands in Phishing Attacks
ChatGPT has become a hot target for phishing attacks, entering the top 10 most impersonated brands in just the second quarter of 2026, with scammers sending fake emails that mimic OpenAI's billing notices to steal sensitive info. This new trend signals where attackers are focusing their efforts next.

Microsoft Battles Exchange Online Mailbox Quarantine Glitch
Microsoft is working to resolve a frustrating glitch in Exchange Online that has caused some mailboxes to be incorrectly quarantined, blocking users from receiving emails and disrupting access to calendars. The issue, which began on July 19, has left affected users unable to send or receive emails and access their calendars.

Microsoft Ends Exchange 2016, 2019 Security Updates in October
Microsoft is ending security updates for Exchange Server 2016 and 2019 in October 2026, with no further extensions available, even for those currently in Period 2 of the Extended Security Update program. This marks the final cutoff for support, leaving organizations without updates after that date.

Authorities Disrupt Kratos Phishing Platform in Global Operation
In a major global crackdown, authorities have shut down Kratos, a notorious phishing-as-a-service platform that helped cybercriminals create fake Microsoft login pages to steal sensitive info. The takedown has disrupted a key tool used by over 1,800 customers to commit crimes like business email compromise and data theft.

Hackers Exploit SharePoint Flaw to Steal Machine Keys
Hackers have already started exploiting a recently discovered SharePoint flaw, CVE-2026-50522, to steal machine keys, with live attempts captured by global honeypots just hours after proof-of-concept exploit code was released. This vulnerability allows remote attackers to execute code without authentication, making it a serious threat.

SharePoint Flaw CVE-2026-50522 Sees Active Exploitation After PoC Release
Attackers are actively exploiting a critical SharePoint vulnerability, CVE-2026-50522, using a single request to gain persistent access by pulling SharePoint machine keys. This flaw, patched by Microsoft in July, has a CVSS score of 9.8 and allows attackers to inject and execute code remotely on the SharePoint Server.

Microsoft Offers Manual Fix for WSUS Sync Delays
Microsoft has restored synchronization times and sync operations on WSUS servers for new installations and rebuilds, and is offering a manual fix for those still experiencing delays. The tech giant took swift action to address the issue, which was causing Windows Update scans to fail or time out, starting with a service-side mitigation on July 13.

Unofficial Patches Mitigate Windows Zero-Day Flaw
Microsoft is investigating a newly discovered Windows zero-day flaw, dubbed LegacyHive, and is working to update impacted products to protect customers as soon as possible. A researcher disclosed the vulnerability, along with a proof-of-concept exploit, on the same day as Microsoft's July 2024 Patch Tuesday updates.

Microsoft Tackles WSUS Sync Delays with Urgent Mitigations
Microsoft has confirmed a known issue causing significant disruptions to Windows Server Update Services (WSUS) synchronization, with synchronization times increasing or sync operations timing out on affected servers. The issue, which began recently and worsened on July 13, 2026, prevents admins from deploying the latest Windows updates via WSUS or Configuration Manager.

Microsoft Releases Fix for Dell PC Shutdowns Tied to Windows Update
Got a Dell PC that's been shutting down unexpectedly after a recent Windows update? Microsoft's just released a fix for the issue, which was causing a range of problems including poor performance, overheating, and battery drain.