Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

GBHackers general Microsoft Aug 17

Misconfigured Microsoft Power Pages Likely Exposed 27 Million Records to ExfilSquad

A suspected Microsoft Power Pages configuration failure has been linked to the exposure of roughly 27 million records across 13 organizations, after the data...

T1041

GBHackers → Details

BleepingComputer general Microsoft Aug 17

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now ...

1 IOC

BleepingComputer → Details

GBHackers general Microsoft Linux Aug 17

HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections

HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit th...

GBHackers → Details

Security Affairs general Microsoft Aug 17

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen

A seller claims 1.7M McDonald’s employee records were stolen from Azure.

Security Affairs → Details

GBHackers general Microsoft Google Aug 17

Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed...

GBHackers → Details

SecurityWeek general Microsoft Aug 17

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Compan...

T1041

SecurityWeek → Details

GBHackers general Microsoft Apple VMware Zoom Aug 17

Weekly Recap! – Top 50 Biggest Cybersecurity Stories of the Week: Apple Spyware, Zoom Zero-Click RCE, VMware vCenter Exploits, Microsoft Patch Day & More

Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from Aug...

GBHackers → Details

GBHackers general Microsoft Aug 17

12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace

A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what a...

GBHackers → Details

Help Net Security general Microsoft Aug 17

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without phy...

Help Net Security → Details

GBHackers general Microsoft Aug 17

McDonald’s, Vodafone Hit in Massive Azure Credential Theft Campaign

A threat actor using the alias “TheHatman” is allegedly selling large corporate employee directories that were allegedly extracted from Microsoft Azure and E...

T1078

GBHackers → Details

Security Affairs general Microsoft Linux Aug 16

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMy...

Security Affairs → Details

GBHackers general Microsoft Aug 15

Microsoft Entra ID Makes Passkeys Default, Retires SMS and Voice MFA in 2027 for Better Security

Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice mu...

GBHackers → Details

GBHackers general Microsoft Linux Aug 15

Download More RAM Attack Bypasses Windows VBS, HVCI and Disables Microsoft Defender

A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected Code I...

T1068 1 IOC

GBHackers → Details

GBHackers general Microsoft Aug 15

Microsoft Copilot App Overhaul Merges Personal Chats and Ends Podcasts, Deep Research

Microsoft is reshaping its consumer and productivity AI strategy with a major update to its Copilot application, merging personal chat histories and generate...

GBHackers → Details

SC Media general Microsoft Amazon Cisco Aug 14

CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list

The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the ...

3 IOCs

SC Media → Details

The Hacker News general Microsoft Linux Aug 14

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kerne...

The Hacker News → Details

The Hacker News general Microsoft Google Aug 14

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Micro...

The Hacker News → Details

SC Media general Microsoft Aug 14

DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign

Initial access is gained through fake job offers and PDF viewer downloads.

SC Media → Details

The Hacker News general Microsoft Google Aug 14

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-...

T1566 T1566.002

The Hacker News → Details

CSO Online enterprise Microsoft Aug 14

Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system ...

CSO Online → Details

«Previous page 1 ... 4 5 6 7 8 ... 26 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA