Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

Microsoft Security Blog vendor Microsoft NEW 1h ago

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizati...

T1078

Microsoft Security Blog → Details

The Hacker News general Microsoft NEW 5h ago

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked a...

T1566

The Hacker News → Details

CSO Online enterprise Microsoft Google 9h ago

Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs

Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmo...

CSO Online → Details

SecurityWeek general Microsoft 13h ago

Critical Flaw Led to Azure Cosmos DB Pwnage

Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azur...

SecurityWeek → Details

CSO Online enterprise Microsoft 13h ago

5 key priorities for your Black Hat agenda — and what to avoid

Two major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991 by then CEO Jim Bidzos o...

CSO Online → Details

GBHackers general Microsoft 16h ago

CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases

A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, incl...

GBHackers → Details

CSO Online enterprise Microsoft 20h ago

Microsoft confirms an AI worm is propagating through Copilot and other MS apps

A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and C...

CSO Online → Details

CSO Online enterprise Microsoft 20h ago

Copilot worm can spread through Microsoft Word docs

An “AI worm” can spread through Microsoft Word documents using Copilot as a vector, a prominent Norwegian AI researcher reported on Tuesday. The report from ...

CSO Online → Details

Elastic Security Labs research Microsoft 22h ago

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

Elastic Defend automatically generates and instantly deploys vulnerable driver YARA rules from VirusTotal, LOLDrivers and Microsoft's blocklist, closing the ...

Elastic Security Labs → Details

SC Media general Microsoft Amazon 22h ago

FTC sues Hims & Hers for alleged deceptive privacy practices and data sharing

The lawsuit alleges that Hims & Hers placed pixel-sized trackers from Meta, Snap, Microsoft, Pinterest, Reddit and X on its website.

SC Media → Details

HackRead general Microsoft 23h ago

Top 10 Companies to Hire Power BI Developers in 2026

Compare 10 Power BI development companies for 2026, covering DAX, Microsoft Fabric, data engineering, security, compliance, AI, and enterprise BI project needs.

HackRead → Details

SC Media general Microsoft 1d ago

Critical Azure Cosmos DB flaw risked cross-tenant compromise

Patched Azure Cosmos DB bug threatened Microsoft and customer databases.

SC Media → Details

Microsoft Security Blog vendor Microsoft 1d ago

​​​​What’s new in Microsoft Security: July 2026

This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations dep...

Microsoft Security Blog → Details

BleepingComputer general Microsoft 1d ago

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks t...

BleepingComputer → Details

HackRead general Microsoft 1d ago

Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover

Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it...

HackRead → Details

Help Net Security general Microsoft Proofpoint 1d ago

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Mic...

1 IOC

Help Net Security → Details

The Hacker News general Microsoft 1d ago

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to...

The Hacker News → Details

GBHackers general Microsoft 1d ago

AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat

AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected comm...

GBHackers → Details

Infosecurity Magazine general Microsoft Check Point 1d ago

Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate auth...

T1566

Infosecurity Magazine → Details

CISA Advisories advisories Microsoft Linux 1d ago

o6 Automation open62541

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or p...

T1498

CISA Advisories → Details

1 2 3 ... 11 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA