Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

The Hacker News general Microsoft Jul 22

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used cri...

T1566

The Hacker News → Details

The Hacker News general Microsoft Jul 22

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has ...

T1598

The Hacker News → Details

Security Affairs general Microsoft Jul 21

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vu...

1 IOC

Security Affairs → Details

Qualys Blog vendor Microsoft Qualys Jul 21

Manual Patching Can’t Outrun AI. Automated Remediation Can.

Executive Summary AI is rapidly transforming vulnerability discovery, outpacing many security teams’ ability to adapt. Microsoft’s July 2026 Patch Tuesday ad...

Qualys Blog → Details

The Hacker News general Microsoft Jul 21

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The ...

1 IOC

The Hacker News → Details

The Hacker News general Microsoft Google Jul 21

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye wi...

The Hacker News → Details

Infosecurity Magazine general Microsoft Apple Jul 21

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans

Infosecurity Magazine → Details

Kaspersky Securelist research Microsoft Jul 21

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection v...

Kaspersky Securelist → Details

Zero Day Initiative advisories Microsoft Jul 21

ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 21

ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

The Hacker News general Microsoft Rapid7 Jul 20

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests...

T1566

The Hacker News → Details

HackRead general Microsoft Jul 20

LG Monitors Spotted Installing Adware-Like App on Windows PCs

Connecting certain LG monitors prompts Windows Update to install an LG app without consent, while the software runs at startup and displays McAfee trial adve...

HackRead → Details

The Hacker News general Microsoft Jul 20

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling ou...

The Hacker News → Details

Infosecurity Magazine general Microsoft Jul 20

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealt...

T1071

Infosecurity Magazine → Details

CSO Online enterprise Microsoft Jul 20

New ACR Stealer campaigns use WebDAV, MSHTA to evade detection

Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, a...

T1204

CSO Online → Details

Rapid7 Blog vendor Microsoft Jul 17

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting ...

T1190 1 IOC

Rapid7 Blog → Details

Microsoft Security Blog vendor Microsoft Jul 17

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Mic...

T1195

Microsoft Security Blog → Details

The Hacker News general Microsoft Jul 17

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microso...

T1555 T1598

The Hacker News → Details

Microsoft Security Blog vendor Microsoft Jul 16

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are s...

Microsoft Security Blog → Details

Tenable Blog vendor Microsoft Jul 16

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw r...

T1190 3 IOCs

Tenable Blog → Details

«Previous page 1 ... 38 39 40 41 42 ... 46 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA