Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

BleepingComputer Vulnerability Disclosure Microsoft May 16

Microsoft rejects critical Azure vulnerability report, no CVE issued

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft d...

BleepingComputer →

Security Affairs CVE Microsoft May 16

U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog

The U.S.

1 IOC

Security Affairs →

Security Affairs Campaigns Microsoft May 16

Russian APT Turla builds long-term access tool with Kazuar Botnet evolution

Russia-linked APT group Turla turned its Kazuar malware into a stealthy P2P botnet for long-term access to compromised systems. Russia-linked APT group Turla...

Security Affairs →

GBHackers Malware Microsoft Linux May 16

JDownloader Website Hack Exposes Windows and Linux Users to Malicious Installers

A popular open-source download manager trusted by millions suddenly became a malware delivery platform after attackers compromised its official website, repl...

T1598

GBHackers →

Security Affairs Zero-Day Microsoft Red Hat Linux May 15

Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K

Day two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities over two days.

Security Affairs →

SC Media Zero-Day Microsoft May 15

Microsoft warns of active exploitation of new Exchange Server zero-day vulnerability

The vulnerability, a cross-site scripting flaw with a CVSS score of 8.1, specifically impacts Outlook Web Access (OWA).

SC Media →

SC Media General Microsoft Cisco May 15

Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581

SC Media →

CSO Online Zero-Day Microsoft May 15

Exchange Server zero-day vulnerability can be triggered by opening a malicious email

A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon ...

T1598

CSO Online →

BleepingComputer Zero-Day Microsoft Red Hat Linux May 15

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple ...

BleepingComputer →

HackRead Malware Microsoft May 15

Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4

Hackers are hiding XWorm malware in PyInstaller files to bypass Windows security, steal data and remotely control devices through ads.

HackRead →

BleepingComputer General Microsoft May 15

Microsoft caves in: Edge to stop loading passwords in memory on startup

Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup. [.

BleepingComputer →

BleepingComputer General Microsoft May 15

Microsoft Edge to stop loading cleartext passwords in memory on startup

Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup. [.

BleepingComputer →

Security Affairs Zero-Day Microsoft May 15

CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

Microsoft warned that attackers are exploiting a new Exchange Server zero-day vulnerability, tracked as CVE-2026-42897, in the wild. Microsoft warned that th...

1 IOC

Security Affairs →

Infosecurity Magazine Zero-Day Microsoft May 15

Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers

The zero-day vulnerability affects on-premises installations for all versions of Exchange Server 2016, 2019 and Subscription Edition

Infosecurity Magazine →

BleepingComputer General Microsoft May 15

Microsoft to automatically roll back faulty Windows drivers

Microsoft is introducing a new Windows Update capability that will allow it to remotely roll back problematic Windows drivers delivered through Windows Updat...

BleepingComputer →

GBHackers Vulnerability Disclosure Microsoft May 15

Hackers Exploit OAuth Device Flow to Steal Microsoft 365 Tokens

Hackers are rapidly weaponizing a little-known Microsoft authentication feature to hijack enterprise accounts, as device code phishing surges across the thre...

T1566

GBHackers →

SecurityWeek Zero-Day Microsoft May 15

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions. The post Microsoft Warns o...

1 IOC

SecurityWeek →

CISA Advisories CVE Microsoft May 15

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42897 Microsoft...

1 IOC

CISA Advisories →

HackRead Data Breach Microsoft May 15

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

Hackers are exploiting Outlook calendar invites and device code phishing to steal M365 session tokens, bypass MFA and breach enterprise accounts.

T1566

HackRead →

GBHackers Vulnerability Disclosure Microsoft May 15

Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks

Microsoft has revealed a stealthy intrusion campaign where attackers bypassed traditional malware and exploits, instead abusing trusted enterprise tools to s...

GBHackers →

«Previous page 1 ... 5 6 7 8 9 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA