Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

Zero Day Initiative CVE Microsoft May 12

ZDI-26-309: Microsoft Windows Message Queueing Double Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows that run Message Queueing. An attacker must f...

T1548 T1068 1 IOC

Zero Day Initiative →

BleepingComputer General Microsoft May 11

New GhostLock tool abuses Windows API to block file access

A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to bl...

BleepingComputer →

SC Media General Microsoft Apple May 11

Smartphone users increasingly forgo paid antivirus protection

A recent survey by Cybernews indicates that only 18% of mobile phone users in America pay for third-party antivirus software, with many trusting the built-in...

SC Media →

CSO Online Malware Microsoft May 11

Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads

A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being re...

CSO Online →

CSO Online Vulnerability Disclosure Microsoft Linux May 11

New ‘Dirty Frag’ exploit targets Linux kernel for root access

A newly disclosed Linux privilege escalation issue dubbed “Dirty Frag” is giving attackers a cleaner path to post-compromise escalation to root privileges. A...

T1548

CSO Online →

GBHackers Campaigns Microsoft May 11

Fake Claude Campaign Uses PlugX-Style DLL Sideloading Chain

Hackers are abusing a fake Claude AI download site to deliver a PlugX‑style DLL sideloading chain that ultimately deploys a new Windows backdoor dubbed “Beag...

T1189

GBHackers →

HackRead Vulnerability Disclosure Microsoft May 11

Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites

Hackers are abusing Vercel GenAI to create convincing phishing sites that mimic major brands, including Microsoft, Adidas, and Nike, making scams harder to d...

T1566

HackRead →

GBHackers General Microsoft Amazon May 11

Microsoft 365 Copilot Flaws Could Let Attackers Access Sensitive Data

Microsoft has disclosed a trio of critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. Release...

GBHackers →

GBHackers Campaigns Microsoft May 11

Trending Hugging Face Repo With 200K Downloads Spreads Windows Malware

A malicious Hugging Face repository, Open-OSS/privacy-filter, that abused the platform’s trust and trending algorithm to deliver a sophisticated Rust-based i...

GBHackers →

The Hacker News General Microsoft Amazon May 11

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deli...

The Hacker News →

GBHackers Ransomware Microsoft May 11

Windows CreateFileW API Flaw Could Let Attackers Lock SMB Files at Scale

The multi-billion-dollar ransomware defence industry operates on a fundamental assumption: to cause catastrophic operational damage, malicious actors must wr...

GBHackers →

GBHackers Campaigns Microsoft May 11

Weaponized JPEG file Drops Trojanized ScreenConnect Malware

Hackers are abusing a weaponized JPEG file to quietly install a trojanized version of the ConnectWise ScreenConnect remote‑access tool on Windows systems, en...

T1078

GBHackers →

Help Net Security General Microsoft Linux May 11

Rustinel: Open-source endpoint detection for Windows and Linux

Open-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders r...

Help Net Security →

Security Affairs Malware Microsoft Linux May 10

Official JDownloader site served malware to Windows and Linux users between May 6 and May 7

JDownloader website was hacked to distribute malicious Windows and Linux installers carrying a Python RAT between May 6–7, 2026. JDownloader official website...

T1195

Security Affairs →

Help Net Security Data Breach Microsoft Google Zoom May 10

Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someon...

Help Net Security →

BleepingComputer Malware Microsoft Linux May 9

JDownloader site hacked to replace installers with Python RAT malware

The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Win...

BleepingComputer →

BleepingComputer Malware Microsoft May 9

Fake OpenAI repository on Hugging Face pushes infostealer malware

A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing ...

BleepingComputer →

GBHackers Campaigns Microsoft SAP May 9

TCLBANKER Malware Leverages WhatsApp and Outlook Worm Features in Active Attacks

A sophisticated Brazilian banking trojan named TCLBANKER, deployed through a trojanized Logitech installer and capable of hijacking victims’ WhatsApp and Out...

GBHackers →

HackRead Campaigns Microsoft Apple May 8

Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam

Microsoft researchers warn of a new ClickFix campaign targeting macOS with fake guides on Medium and Craft to deploy AMOS and SHub Stealer via Terminal comma...

HackRead →

SC Media General Microsoft May 8

Microsoft Edge password saving practice raises security concerns

The browser reportedly converts saved passwords into plaintext within the computer's memory as soon as the application launches, making them vulnerable to un...

SC Media →

«Previous page 1 ... 10 11 12 13 14 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA