Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

Microsoft Security Blog vendor Microsoft Jul 16

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agen...

T1598

Microsoft Security Blog → Details

CISA Advisories advisories Microsoft Fortinet Jul 16

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

T1059 3 IOCs

CISA Advisories → Details

Microsoft Security Blog vendor Microsoft Jul 16

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Intel Jul 15

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a s...

Microsoft Security Blog → Details

Infosecurity Magazine general Microsoft Jul 15

Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass

Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine

Infosecurity Magazine → Details

Infosecurity Magazine general Microsoft Jul 15

Microsoft Patches 570 CVEs in Record Patch Tuesday

Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and ...

Infosecurity Magazine → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability

This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User in...

1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the abi...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to explo...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exp...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Microsoft Jul 15

ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is not required to exp...

T1190 1 IOC

Zero Day Initiative → Details

Rapid7 Blog vendor Microsoft Rapid7 Jul 14

Patch Tuesday - July 2026

Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday, including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploi...

Rapid7 Blog → Details

Qualys Blog vendor Microsoft Adobe Jul 14

Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 

Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose signifi...

Qualys Blog → Details

Krebs on Security general Microsoft Amazon Intel Jul 14

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the nu...

Krebs on Security → Details

AWS Security Blog vendor Microsoft Jul 14

Security Hub adds AI workload protection and multicloud support for Microsoft Azure

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritiz...

AWS Security Blog → Details

Tenable Blog vendor Microsoft Jul 14

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

56Critical 510Important 3Moderate 0Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, ...

2 IOCs

Tenable Blog → Details

Proofpoint Blog vendor Microsoft Jul 14

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Proofpoint Blog → Details

Rapid7 Blog vendor Microsoft Rapid7 Jul 14

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when cha...

T1190 T1556 1 IOC

Rapid7 Blog → Details

«Previous page 1 ... 39 40 41 42 43 ... 46 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA