Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

SecurityWeek General Microsoft 3d ago

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition. The post Microsoft Patches Exploited UnDefend and ...

SecurityWeek →

BleepingComputer Zero-Day Microsoft 3d ago

Microsoft warns of new Defender zero-days exploited in attacks

On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. [.

BleepingComputer →

GBHackers Malware Microsoft 3d ago

BadIIS Malware Hijacks IIS Servers to Redirect Users to Illicit Sites

A new variant of the BadIIS malware that hijacks Microsoft IIS web servers to redirect users to illicit websites, highlighting an evolving malware-as-a-servi...

T1588

GBHackers →

Help Net Security TTPs Microsoft NVIDIA 3d ago

AI red teaming agents change how LLMs get tested

Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Cresc...

Help Net Security →

GBHackers General Microsoft 3d ago

New GhostTree Attack Causes EDR Tools to Hang, Leaving Files Unscanned

A newly disclosed attack technique dubbed “GhostTree” is raising concerns among defenders after researchers demonstrated how it can disrupt endpoint detectio...

GBHackers →

The Hacker News Data Breach Microsoft GitHub 3d ago

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poison...

The Hacker News →

CSO Online Zero-Day Microsoft 4d ago

Microsoft is working on a patch for ‘YellowKey’ attack on Bitlocker, offers temporary fix

Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitl...

1 IOC

CSO Online →

Cyberscoop General Microsoft 4d ago

Meet Rampart and Clarity, Microsoft’s new red team combo AI agents

Microsoft’s AI red team lead talked to CyberScoop about the goals behind open sourcing a pair of security tools meant for developers and incident responders....

Cyberscoop →

Microsoft Security Blog Malware Microsoft Amazon GitHub Linux Kubernetes 4d ago

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes durin...

T1078

Microsoft Security Blog →

The Hacker News General Microsoft Intel 4d ago

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (A...

The Hacker News →

Microsoft Security Blog General Microsoft 4d ago

Securing the gaming culture of cultures

Read about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities. The post Securing the gaming culture ...

Microsoft Security Blog →

CSO Online Data Breach Microsoft GitHub 4d ago

GitHub admits major source code leak after 3,800 internal repositories breached

Microsoft’s GitHub has suffered what appears to be its biggest ever security breach after confirming that attackers exfiltrated code from around 3,800 of the...

T1041

CSO Online →

SecurityWeek General Microsoft 4d ago

Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass

The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches. The post Microsoft Rolls Out Mitigati...

SecurityWeek →

Security Affairs CVE Microsoft 4d ago

Microsoft issues YellowKey mitigation, no patch yet

Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN.

1 IOC

Security Affairs →

Microsoft Security Blog General Microsoft 4d ago

Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow

The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well ...

T1598

Microsoft Security Blog →

Cyberscoop General Microsoft GitHub 4d ago

GitHub says internal repositories were taken in poisoned VS Code extension attack

GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension...

T1041

Cyberscoop →

The Hacker News Ransomware Microsoft 4d ago

Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver mali...

The Hacker News →

SC Media TTPs Microsoft 4d ago

Storm-2949 actor targets Microsoft 365 and Azure environments

Storm-2949 initiates attacks by targeting users with privileged roles, such as IT personnel or senior leadership, using social engineering tactics to obtain ...

T1204

SC Media →

SC Media General Microsoft 4d ago

Microsoft to phase out SMS authentication for account recovery

Microsoft has announced it will begin phasing out SMS-based authentication and account recovery, citing it as a leading source of fraud.

SC Media →

SC Media Malware Microsoft 4d ago

Microsoft disrupts Fox Tempest malware-signing service

Fox Tempest operated a platform called signspace[.]cloud, which allowed threat actors to obtain short-lived Microsoft-issued certificates via Artifact Signing.

SC Media →

«Previous page 1 2 3 4 5 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA