Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

CSO Online enterprise Microsoft Jul 20

New ACR Stealer campaigns use WebDAV, MSHTA to evade detection

Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, a...

T1204

CSO Online → Details

Rapid7 Blog vendor Microsoft Jul 17

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting ...

T1190 1 IOC

Rapid7 Blog → Details

Microsoft Security Blog vendor Microsoft Jul 17

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Mic...

T1195

Microsoft Security Blog → Details

The Hacker News general Microsoft Jul 17

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microso...

T1555 T1598

The Hacker News → Details

Microsoft Security Blog vendor Microsoft Jul 16

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are s...

Microsoft Security Blog → Details

Tenable Blog vendor Microsoft Jul 16

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw r...

T1190 3 IOCs

Tenable Blog → Details

Microsoft Security Blog vendor Microsoft Jul 16

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agen...

T1598

Microsoft Security Blog → Details

CISA Advisories advisories Microsoft Fortinet Jul 16

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

T1059 3 IOCs

CISA Advisories → Details

Microsoft Security Blog vendor Microsoft Jul 16

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Intel Jul 15

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a s...

Microsoft Security Blog → Details

Infosecurity Magazine general Microsoft Jul 15

Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass

Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine

Infosecurity Magazine → Details

Infosecurity Magazine general Microsoft Jul 15

Microsoft Patches 570 CVEs in Record Patch Tuesday

Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and ...

Infosecurity Magazine → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability

This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User in...

1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the abi...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to explo...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exp...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exp...

T1190 1 IOC

Zero Day Initiative → Details

Rapid7 Blog vendor Microsoft Rapid7 Jul 14

Patch Tuesday - July 2026

Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday, including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploi...

Rapid7 Blog → Details

«Previous page 1 ... 20 21 22 23 24 ... 26 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA