Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

Microsoft Security Blog Supply Chain Microsoft 5d ago

Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us 

A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seve...

T1195

Microsoft Security Blog →

CSO Online DDoS Microsoft Cloudflare F5 Apache 5d ago

HTTP/2’s speed abused to slow webserver performance in DoS attack

Security researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of ...

T1498

CSO Online →

SC Media General Microsoft Docker 5d ago

Microsoft introduces execution containers for AI agents

MXC functions as an SDK and policy model embedded within Windows and WSL, acting as a declarative boundary system for AI agents.

SC Media →

Infosecurity Magazine Malware Microsoft 5d ago

Infosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft Warns

Microsoft Detection and Response Team (DART) details how it has uncovered malicious AI applications as cyber criminals manipulate organizations adopting AI t...

Infosecurity Magazine →

SC Media Campaigns Microsoft 5d ago

Stock exchange executive’s Outlook mailbox stolen over course of 5 months

The approximately 150-day espionage campaign incrementally exfiltrated emails to cloud services.

T1041

SC Media →

BleepingComputer General Microsoft 5d ago

Microsoft blames unexpected Windows driver updates on caching issue

On Wednesday, Microsoft fixed an issue that caused some Windows devices to install driver updates without notice despite policies configured to prevent auto-...

BleepingComputer →

The Record Vulnerability Disclosure Microsoft GitHub 5d ago

Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process

The security researcher, Ammar Askar, released the new proof-of-concept exploit on his personal blog — alongside the public tracker for issues in VS Code — g...

The Record →

GBHackers Zero-Day Microsoft Linux 5d ago

Comodo Internet Security 0-Day Flaw Triggers Windows System Crashes

A remotely exploitable zero-day vulnerability in Comodo Internet Security’s kernel-level firewall driver allows attackers to crash Windows systems with a sin...

GBHackers →

Security Affairs Vulnerability Disclosure Microsoft 5d ago

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Gamaredon exploits a WinRAR flaw to drop modular, nearly fileless malware on Ukrainian targets, hiding payloads in Windows streams and resolving C2s via Tele...

Security Affairs →

GBHackers Campaigns Microsoft 5d ago

Stock Exchange Executive’s Outlook Targeted in Credential Theft Attack

A prolonged and highly targeted espionage campaign has been uncovered involving the compromise of a senior executive’s Microsoft Outlook account at a major g...

T1078

GBHackers →

The Hacker News Campaigns Microsoft Broadcom 5d ago

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in smal...

The Hacker News →

Security Affairs Zero-Day Microsoft GitHub 5d ago

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

A researcher publicly released a VS Code exploit within hours, citing past disputes with Microsoft over bug handling. The security researcher Ammar Askar fou...

Security Affairs →

SecurityWeek Vulnerability Disclosure Microsoft GitHub 5d ago

VS Code Vulnerability Allows One-Click GitHub Token Theft

A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. The post VS Code Vulnerability Al...

SecurityWeek →

GBHackers Phishing Microsoft Okta Intel 5d ago

Kali365 PhaaS Expands to Okta, MAX Messenger Attacks

The Kali365 phishing-as-a-service (PhaaS) platform has significantly expanded its operational scope, moving beyond Microsoft 365 token theft to target Okta s...

T1566

GBHackers →

SANS ISC General Microsoft 5d ago

Microsoft's Coreutils for Windows, (Thu, Jun 4th)

I&#;x26;#;39;ve been using the GnuWin32 CoreUtils for Windows for many years now (it gives you many *nix core commands on Windows).

SANS ISC →

GBHackers General Microsoft 5d ago

Microsoft Introduces Always-On AI Agent Scout for Teams, Outlook, and More

Microsoft has introduced an always-on AI agent named “Scout,” marking the debut of a new category of enterprise automation called “Autopilots.

GBHackers →

Zero Day Initiative CVE Microsoft 5d ago

ZDI-26-331: (Pwn2Own) Microsoft Edge Feedback Log File Handling Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit thi...

T1190 1 IOC

Zero Day Initiative →

Zero Day Initiative CVE Microsoft 5d ago

ZDI-26-330: (Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability

This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required...

1 IOC

Zero Day Initiative →

Zero Day Initiative CVE Microsoft 5d ago

ZDI-26-329: (Pwn2Own) Microsoft Edge Origin Validation Error Security Bypass Vulnerability

This vulnerability allows remote attackers to access restricted functionality on affected installations of Microsoft Edge. User interaction is required to ex...

1 IOC

Zero Day Initiative →

CSO Online Vulnerability Disclosure Microsoft GitHub 5d ago

Hole in GitHub’s browser-based VSCode editor could lead to stolen token

A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher. The is...

T1598

CSO Online →

«Previous page 1 2 3 4 5 6 ... 27 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA