Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

CSO Online enterprise Microsoft Jul 23

Microsoft’s 3-day patching directive comes with added operational risk

Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise...

T1598

CSO Online → Details

Help Net Security general Microsoft Intel Jul 23

Shadow AI is becoming enterprise security’s biggest blind spot

Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, ...

T1598

Help Net Security → Details

SC Media general Microsoft Jul 22

Microsoft ends extended security updates for Exchange 2016 and 2019 in October 2026

The Exchange Server team confirmed that there will be no further extensions beyond the current Period 2 ESU program, which concludes in October 2026.

SC Media → Details

CSO Online enterprise Microsoft Jul 22

Critical Zimbra security update fixes 9 vulnerabilities

Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute m...

CSO Online → Details

Microsoft Security Blog vendor Microsoft Jul 22

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technic...

Microsoft Security Blog → Details

CISA Advisories advisories Microsoft Check Point Jul 22

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-16232 Check P...

2 IOCs

CISA Advisories → Details

BleepingComputer general Microsoft Jul 22

Microsoft to stop Exchange 2016 / 2019 security updates in October

Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in...

BleepingComputer → Details

The Hacker News general Microsoft Jul 22

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used cri...

T1566

The Hacker News → Details

The Hacker News general Microsoft Jul 22

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has ...

T1598

The Hacker News → Details

Security Affairs general Microsoft Jul 21

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vu...

1 IOC

Security Affairs → Details

Qualys Blog vendor Microsoft Qualys Jul 21

Manual Patching Can’t Outrun AI. Automated Remediation Can.

Executive Summary AI is rapidly transforming vulnerability discovery, outpacing many security teams’ ability to adapt. Microsoft’s July 2026 Patch Tuesday ad...

Qualys Blog → Details

The Hacker News general Microsoft Jul 21

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The ...

1 IOC

The Hacker News → Details

The Hacker News general Microsoft Google Jul 21

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye wi...

The Hacker News → Details

Infosecurity Magazine general Microsoft Apple Jul 21

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans

Infosecurity Magazine → Details

Kaspersky Securelist research Microsoft Jul 21

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection v...

Kaspersky Securelist → Details

Zero Day Initiative advisories Microsoft Jul 21

ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 21

ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

The Hacker News general Microsoft Rapid7 Jul 20

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests...

T1566

The Hacker News → Details

HackRead general Microsoft Jul 20

LG Monitors Spotted Installing Adware-Like App on Windows PCs

Connecting certain LG monitors prompts Windows Update to install an LG app without consent, while the software runs at startup and displays McAfee trial adve...

HackRead → Details

The Hacker News general Microsoft Jul 20

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling ou...

The Hacker News → Details

«Previous page 1 ... 19 20 21 22 23 ... 26 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA