Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

Help Net Security Zero-Day Microsoft Google Apple Linux 12h ago

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)

Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that...

1 IOC

Help Net Security →

CSO Online Advisory Microsoft Google Intel 12h ago

Security shifts to the human layer as AI scams surge

Cybercriminals are increasingly reshaping familiar social-engineering campaigns around the way employees use AI, with separate advisories from Microsoft and ...

T1204

CSO Online →

GBHackers General Microsoft 13h ago

Ghost-Sender Flaw Exposes Exchange Online Users to Sender Spoofing Attacks

A newly disclosed “Ghost-Sender” flaw is exposing Microsoft Exchange Online environments to large-scale email spoofing attacks, allowing threat actors to byp...

GBHackers →

GBHackers General Microsoft 13h ago

Microsoft Entra Agent ID Logs Expose Suspicious Assistive Agent Activity

Microsoft Entra Agent ID logs have exposed a subtle but consequential threat vector: assistive agents using the OAuth On-Behalf-Of (OBO) flow to act with del...

GBHackers →

Zero Day Initiative CVE Microsoft 18h ago

ZDI-26-339: Microsoft Windows Narrator Braille Support brlapi Exposed Dangerous Function Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative →

Unit 42 General Microsoft 1d ago

When “Hi, This Is IT” Comes Through Microsoft Teams

Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security.

Unit 42 →

SC Media General Microsoft 1d ago

Silverfort integrates identity controls with Microsoft Copilot Studio agents

The new integration evaluates every access request made by a Copilot agent in real time, providing a decision before the action is executed.

SC Media →

Help Net Security General Microsoft 1d ago

Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows

Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of mont...

Help Net Security →

Microsoft Security Blog General Microsoft 1d ago

AI brands as bait: How threat actors are using the AI hype in social engineering

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. T...

T1204

Microsoft Security Blog →

Help Net Security General Microsoft Apple 1d ago

RidgeBot 7.0 automates Active Directory attack simulations for security validation

Ridge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active Di...

Help Net Security →

GBHackers Vulnerability Disclosure Microsoft Google Apple Amazon Linux 1d ago

Google Fixes 429 Chrome Vulnerabilities, Including 22 Critical Bugs

Google has released Chrome 149 to the stable channel, addressing a significant batch of 429 security vulnerabilities across Windows, macOS, and Linux, includ...

T1190

GBHackers →

GBHackers Vulnerability Disclosure Microsoft 1d ago

Internet Explorer WebBrowser Control Abuse Lets Attackers Convert Clicks Into RCE

Internet Explorer’s legacy WebBrowser control can be abused to turn seemingly harmless user clicks into full remote code execution (RCE), even on systems tha...

T1190

GBHackers →

The Hacker News Campaigns Microsoft Linux 1d ago

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families co...

The Hacker News →

The Hacker News Supply Chain Microsoft 1d ago

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are ...

T1195

The Hacker News →

GBHackers TTPs Microsoft 1d ago

EDRChoker Tool Abuses Windows QoS Policies to Disrupt Endpoint Security Tools

A newly disclosed red-team tool dubbed “EDRChoker” is drawing attention across the cybersecurity community for its novel approach to disrupting Endpoint Dete...

T1562

GBHackers →

GBHackers General Microsoft GitHub 1d ago

Microsoft Warns Claude Code GitHub Action May Expose CI/CD Secrets

Anthropic’s Claude Code GitHub Action could unintentionally expose CI/CD workflow secrets when AI agents process untrusted GitHub content. The risk arises be...

T1598

GBHackers →

Help Net Security Campaigns Microsoft 1d ago

When attacks spread too far: Lessons from real cyber attack case studies

In this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during ...

T1566

Help Net Security →

Help Net Security General Microsoft GitHub 1d ago

GitHub Copilot app launches as desktop home for AI coding agents

GitHub introduced the Copilot app, a desktop application built for working with AI coding agents, at Microsoft Build 2026. The release expands GitHub’s Copil...

Help Net Security →

BleepingComputer General Microsoft Intel 2d ago

Hands on with Intelligent Terminal, an AI-powered Windows Terminal

Microsoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without int...

BleepingComputer →

HackRead Campaigns Microsoft 3d ago

New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams

Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication an...

T1566

HackRead →

«Previous page 1 2 3 4 ... 27 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA