Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

HackRead general Microsoft Aug 5

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishi...

T1566

HackRead → Details

GBHackers general Microsoft Aug 5

7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen

7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen never r...

GBHackers → Details

The Hacker News general Microsoft Fortinet Aug 5

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and ne...

T1195

The Hacker News → Details

GBHackers general Microsoft Aug 5

Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment

Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate W...

GBHackers → Details

GBHackers general Microsoft Google Aug 5

1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code

A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted codin...

T1190

GBHackers → Details

GBHackers general Microsoft Barracuda Aug 5

Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500

A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful la...

T1598

GBHackers → Details

Microsoft Security Blog vendor Microsoft Aug 4

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates...

T1195

Microsoft Security Blog → Details

BleepingComputer general Microsoft Aug 4

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing target...

T1566 T1557 T1598

BleepingComputer → Details

SC Media general Microsoft Aug 4

Russia-linked Midnight Blizzard targets hotel Wi-Fi networks in US, Europe

Hotel Wi-Fi phishing campaign targets business travelers, Microsoft warns.

T1566

SC Media → Details

Microsoft Security Blog vendor Microsoft Aug 4

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Tru...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Aug 4

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or sprea...

Microsoft Security Blog → Details

Help Net Security general Microsoft GitHub Aug 4

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. ...

T1204

Help Net Security → Details

Fortinet Blog vendor Microsoft Aug 4

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolv...

T1195

Fortinet Blog → Details

The Record general Microsoft Aug 4

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency...

The Record → Details

CSO Online enterprise Microsoft Amazon Aug 4

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute...

CSO Online → Details

Help Net Security general Microsoft Intel Aug 4

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at ...

Help Net Security → Details

Help Net Security general Microsoft Aug 4

Securonix enhances Unified Defense SIEM with AI agent detection and lower data costs

Securonix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Resp...

Help Net Security → Details

Help Net Security general Microsoft Aug 4

Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package...

1 IOC

Help Net Security → Details

GBHackers general Microsoft Aug 4

ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers

ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, an...

GBHackers → Details

SecurityWeek general Microsoft Aug 4

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Pai...

SecurityWeek → Details

«Previous page 1 ... 12 13 14 15 16 ... 26 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA